Audits
Settings
Links
Tenable Cloud
Tenable Community & Support
Tenable University
Theme
Light
Dark
Auto
Help
Plugins
Overview
Plugins Pipeline
Newest
Updated
Search
Nessus Families
WAS Families
NNM Families
LCE Families
Tenable OT Security Families
About Plugin Families
Release Notes
Audits
Overview
Newest
Updated
Search Audit Files
Search Items
References
Authorities
Documentation
Download All Audit Files
Indicators
Overview
Search
Indicators of Attack
Indicators of Exposure
CVEs
Overview
Newest
Updated
Search
Attack Path Techniques
Overview
Search
Links
Tenable Cloud
Tenable Community & Support
Tenable University
Settings
Theme
Light
Dark
Auto
Detections
Plugins
Overview
Plugins Pipeline
Release Notes
Newest
Updated
Search
Nessus Families
WAS Families
NNM Families
LCE Families
Tenable OT Security Families
About Plugin Families
Audits
Overview
Newest
Updated
Search Audit Files
Search Items
References
Authorities
Documentation
Download All Audit Files
Indicators
Overview
Search
Indicators of Attack
Indicators of Exposure
Analytics
CVEs
Overview
Newest
Updated
Search
Attack Path Techniques
Overview
Search
Audits
References
CCI
CCI-004066
CCI
CCI|CCI-004066
Title
For password-based authentication, enforce organization-defined composition and complexity rules.
Reference Item Details
Reference:
CCI - DISA Control Correlation Identifier
Category:
2024
Audit Items
View all Reference Audit Items
Name
Plugin
Audit Name
AIOS-16-006500 - Apple iOS/iPadOS 16 must be configured to enforce a minimum password length of six characters.
MDM
MobileIron - DISA Apple iOS/iPadOS 16 v2r1
AIOS-16-006500 - Apple iOS/iPadOS 16 must be configured to enforce a minimum password length of six characters.
MDM
AirWatch - DISA Apple iOS/iPadOS 16 v2r1
AIOS-17-006500 - Apple iOS/iPadOS 17 must be configured to enforce a minimum password length of six characters.
MDM
MobileIron - DISA Apple iOS/iPadOS 17 v2r1
AIOS-17-006500 - Apple iOS/iPadOS 17 must be configured to enforce a minimum password length of six characters.
MDM
AirWatch - DISA Apple iOS/iPadOS 17 v2r1
AIOS-17-006600 - Apple iOS/iPadOS 17 must be configured to not allow passwords that include more than four repeating or sequential characters.
MDM
AirWatch - DISA Apple iOS/iPadOS 17 v2r1
AIOS-17-006600 - Apple iOS/iPadOS 17 must be configured to not allow passwords that include more than four repeating or sequential characters.
MDM
MobileIron - DISA Apple iOS/iPadOS 17 v2r1
AIOS-18-006500 - Apple iOS/iPadOS 18 must be configured to enforce a minimum password length of six characters.
MDM
AirWatch - DISA Apple iOS/iPadOS 18 v1r1
AIOS-18-006500 - Apple iOS/iPadOS 18 must be configured to enforce a minimum password length of six characters.
MDM
MobileIron - DISA Apple iOS/iPadOS 18 v1r1
AIOS-18-006600 - Apple iOS/iPadOS 18 must be configured to not allow passwords that include more than four repeating or sequential characters.
MDM
AirWatch - DISA Apple iOS/iPadOS 18 v1r1
AIOS-18-006600 - Apple iOS/iPadOS 18 must be configured to not allow passwords that include more than four repeating or sequential characters.
MDM
MobileIron - DISA Apple iOS/iPadOS 18 v1r1
AIX7-00-001120 - AIX must enforce password complexity by requiring that at least one upper-case character be used.
Unix
DISA STIG AIX 7.x v3r1
AIX7-00-001121 - AIX must enforce password complexity by requiring that at least one lower-case character be used.
Unix
DISA STIG AIX 7.x v3r1
AIX7-00-001122 - AIX must enforce password complexity by requiring that at least one numeric character be used.
Unix
DISA STIG AIX 7.x v3r1
AIX7-00-001123 - AIX must require the change of at least 50% of the total number of characters when passwords are changed.
Unix
DISA STIG AIX 7.x v3r1
AIX7-00-001125 - AIX Operating systems must enforce 24 hours/1 day as the minimum password lifetime.
Unix
DISA STIG AIX 7.x v3r1
AIX7-00-001126 - AIX Operating systems must enforce a 60-day maximum password lifetime restriction.
Unix
DISA STIG AIX 7.x v3r1
AIX7-00-001128 - AIX must use Loadable Password Algorithm (LPA) password hashing algorithm.
Unix
DISA STIG AIX 7.x v3r1
AIX7-00-001129 - AIX must enforce a minimum 15-character password length.
Unix
DISA STIG AIX 7.x v3r1
AIX7-00-001130 - AIX must enforce password complexity by requiring that at least one special character be used.
Unix
DISA STIG AIX 7.x v3r1
ALMA-09-035770 - AlmaLinux OS 9 must enforce password complexity by requiring that at least one lowercase character be used.
Unix
DISA CloudLinux AlmaLinux OS 9 STIG v1r1
ALMA-09-035880 - AlmaLinux OS 9 must ensure the password complexity module is enabled in the password-auth file.
Unix
DISA CloudLinux AlmaLinux OS 9 STIG v1r1
ALMA-09-035990 - AlmaLinux OS 9 must ensure the password complexity module in the system-auth file is configured for three retries or less.
Unix
DISA CloudLinux AlmaLinux OS 9 STIG v1r1
ALMA-09-036100 - AlmaLinux OS 9 must enforce password complexity rules for the root account.
Unix
DISA CloudLinux AlmaLinux OS 9 STIG v1r1
ALMA-09-036210 - AlmaLinux OS 9 must enforce password complexity by requiring that at least one uppercase character be used.
Unix
DISA CloudLinux AlmaLinux OS 9 STIG v1r1
ALMA-09-036320 - AlmaLinux OS 9 must enforce password complexity by requiring that at least one special character be used.
Unix
DISA CloudLinux AlmaLinux OS 9 STIG v1r1
ALMA-09-036430 - AlmaLinux OS 9 passwords for new users must have a minimum of 15 characters.
Unix
DISA CloudLinux AlmaLinux OS 9 STIG v1r1
ALMA-09-036540 - AlmaLinux OS 9 passwords must be created with a minimum of 15 characters.
Unix
DISA CloudLinux AlmaLinux OS 9 STIG v1r1
ALMA-09-036650 - AlmaLinux OS 9 must enforce password complexity by requiring that at least one numeric character be used.
Unix
DISA CloudLinux AlmaLinux OS 9 STIG v1r1
ALMA-09-036760 - AlmaLinux OS 9 must require the change of at least four character classes when passwords are changed.
Unix
DISA CloudLinux AlmaLinux OS 9 STIG v1r1
ALMA-09-036870 - AlmaLinux OS 9 must require the maximum number of repeating characters be limited to three when passwords are changed.
Unix
DISA CloudLinux AlmaLinux OS 9 STIG v1r1
ALMA-09-036980 - AlmaLinux OS 9 must require the maximum number of repeating characters of the same character class be limited to four when passwords are changed.
Unix
DISA CloudLinux AlmaLinux OS 9 STIG v1r1
ALMA-09-037090 - AlmaLinux OS 9 must require the change of at least eight characters when passwords are changed.
Unix
DISA CloudLinux AlmaLinux OS 9 STIG v1r1
APPL-14-003007 The macOS system must require passwords contain a minimum of one numeric character.
Unix
DISA Apple macOS 14 (Sonoma) STIG v2r3
APPL-14-003008 The macOS system must restrict maximum password lifetime to 60 days.
Unix
DISA Apple macOS 14 (Sonoma) STIG v2r3
APPL-14-003010 The macOS system must require a minimum password length of 14 characters.
Unix
DISA Apple macOS 14 (Sonoma) STIG v2r3
APPL-14-003011 The macOS system must require passwords contain a minimum of one special character.
Unix
DISA Apple macOS 14 (Sonoma) STIG v2r3
APPL-14-003060 The macOS system must require passwords contain a minimum of one lowercase character and one uppercase character.
Unix
DISA Apple macOS 14 (Sonoma) STIG v2r3
APPL-14-003070 The macOS system must set minimum password lifetime to 24 hours.
Unix
DISA Apple macOS 14 (Sonoma) STIG v2r3
APPL-15-003007 - The macOS system must require that passwords contain a minimum of one numeric character.
Unix
DISA Apple macOS 15 (Sequoia) STIG v1r2
APPL-15-003008 - The macOS system must restrict maximum password lifetime to 60 days.
Unix
DISA Apple macOS 15 (Sequoia) STIG v1r2
APPL-15-003010 - The macOS system must require a minimum password length of 14 characters.
Unix
DISA Apple macOS 15 (Sequoia) STIG v1r2
APPL-15-003011 - The macOS system must require that passwords contain a minimum of one special character.
Unix
DISA Apple macOS 15 (Sequoia) STIG v1r2
APPL-15-003060 - The macOS system must require that passwords contain a minimum of one lowercase character and one uppercase character.
Unix
DISA Apple macOS 15 (Sequoia) STIG v1r2
APPL-15-003070 - The macOS system must set minimum password lifetime to 24 hours.
Unix
DISA Apple macOS 15 (Sequoia) STIG v1r2
ARST-ND-000380 - The Arista network device must enforce a minimum 15-character password length.
Arista
DISA STIG Arista MLS EOS 4.2x NDM v2r1
CASA-ND-000490 - The Cisco ASA must be configured to enforce a minimum 15-character password length.
Cisco
DISA STIG Cisco ASA NDM v2r2
CASA-ND-000520 - The Cisco ASA must be configured to enforce password complexity by requiring that at least one uppercase character be used.
Cisco
DISA STIG Cisco ASA NDM v2r2
CASA-ND-000530 - The Cisco ASA must be configured to enforce password complexity by requiring that at least one lowercase character be used.
Cisco
DISA STIG Cisco ASA NDM v2r2
CASA-ND-000550 - The Cisco ASA must be configured to enforce password complexity by requiring that at least one numeric character be used.
Cisco
DISA STIG Cisco ASA NDM v2r2
CASA-ND-000570 - The Cisco ASA must be configured to enforce password complexity by requiring that at least one special character be used.
Cisco
DISA STIG Cisco ASA NDM v2r2