CCI|CCI-004066

Title

For password-based authentication, enforce organization-defined composition and complexity rules.

Reference Item Details

Category: 2024

Audit Items

View all Reference Audit Items

NamePluginAudit Name
AIOS-16-006500 - Apple iOS/iPadOS 16 must be configured to enforce a minimum password length of six characters.MDMMobileIron - DISA Apple iOS/iPadOS 16 v2r1
AIOS-16-006500 - Apple iOS/iPadOS 16 must be configured to enforce a minimum password length of six characters.MDMAirWatch - DISA Apple iOS/iPadOS 16 v2r1
AIOS-17-006500 - Apple iOS/iPadOS 17 must be configured to enforce a minimum password length of six characters.MDMMobileIron - DISA Apple iOS/iPadOS 17 v2r1
AIOS-17-006500 - Apple iOS/iPadOS 17 must be configured to enforce a minimum password length of six characters.MDMAirWatch - DISA Apple iOS/iPadOS 17 v2r1
AIOS-17-006600 - Apple iOS/iPadOS 17 must be configured to not allow passwords that include more than four repeating or sequential characters.MDMAirWatch - DISA Apple iOS/iPadOS 17 v2r1
AIOS-17-006600 - Apple iOS/iPadOS 17 must be configured to not allow passwords that include more than four repeating or sequential characters.MDMMobileIron - DISA Apple iOS/iPadOS 17 v2r1
AIOS-18-006500 - Apple iOS/iPadOS 18 must be configured to enforce a minimum password length of six characters.MDMAirWatch - DISA Apple iOS/iPadOS 18 v1r1
AIOS-18-006500 - Apple iOS/iPadOS 18 must be configured to enforce a minimum password length of six characters.MDMMobileIron - DISA Apple iOS/iPadOS 18 v1r1
AIOS-18-006600 - Apple iOS/iPadOS 18 must be configured to not allow passwords that include more than four repeating or sequential characters.MDMAirWatch - DISA Apple iOS/iPadOS 18 v1r1
AIOS-18-006600 - Apple iOS/iPadOS 18 must be configured to not allow passwords that include more than four repeating or sequential characters.MDMMobileIron - DISA Apple iOS/iPadOS 18 v1r1
APPL-14-003007 - The macOS system must require passwords contain a minimum of one numeric character.UnixDISA Apple macOS 14 (Sonoma) STIG v2r2
APPL-14-003008 - The macOS system must restrict maximum password lifetime to 60 days.UnixDISA Apple macOS 14 (Sonoma) STIG v2r2
APPL-14-003010 - The macOS system must require a minimum password length of 14 characters.UnixDISA Apple macOS 14 (Sonoma) STIG v2r2
APPL-14-003011 - The macOS system must require passwords contain a minimum of one special character.UnixDISA Apple macOS 14 (Sonoma) STIG v2r2
APPL-14-003060 - The macOS system must require passwords contain a minimum of one lowercase character and one uppercase character.UnixDISA Apple macOS 14 (Sonoma) STIG v2r2
APPL-15-003007 - The macOS system must require that passwords contain a minimum of one numeric character.UnixDISA Apple macOS 15 (Sequoia) STIG v1r1
APPL-15-003008 - The macOS system must restrict maximum password lifetime to 60 days.UnixDISA Apple macOS 15 (Sequoia) STIG v1r1
APPL-15-003010 - The macOS system must require a minimum password length of 14 characters.UnixDISA Apple macOS 15 (Sequoia) STIG v1r1
APPL-15-003011 - The macOS system must require that passwords contain a minimum of one special character.UnixDISA Apple macOS 15 (Sequoia) STIG v1r1
APPL-15-003060 - The macOS system must require that passwords contain a minimum of one lowercase character and one uppercase character.UnixDISA Apple macOS 15 (Sequoia) STIG v1r1
ARST-ND-000380 - The Arista network device must enforce a minimum 15-character password length.AristaDISA STIG Arista MLS EOS 4.2x NDM v2r1
CASA-ND-000490 - The Cisco ASA must be configured to enforce a minimum 15-character password length.CiscoDISA STIG Cisco ASA NDM v2r2
CASA-ND-000520 - The Cisco ASA must be configured to enforce password complexity by requiring that at least one uppercase character be used.CiscoDISA STIG Cisco ASA NDM v2r2
CASA-ND-000530 - The Cisco ASA must be configured to enforce password complexity by requiring that at least one lowercase character be used.CiscoDISA STIG Cisco ASA NDM v2r2
CASA-ND-000550 - The Cisco ASA must be configured to enforce password complexity by requiring that at least one numeric character be used.CiscoDISA STIG Cisco ASA NDM v2r2
CASA-ND-000570 - The Cisco ASA must be configured to enforce password complexity by requiring that at least one special character be used.CiscoDISA STIG Cisco ASA NDM v2r2
CASA-ND-000580 - The Cisco ASA must be configured to require that when a password is changed, the characters are changed in at least eight of the positions within the password.CiscoDISA STIG Cisco ASA NDM v2r2
CISC-ND-000550 - The Cisco router must be configured to enforce a minimum 15-character password length.CiscoDISA STIG Cisco IOS XE Router NDM v3r2
CISC-ND-000550 - The Cisco router must be configured to enforce a minimum 15-character password length.CiscoDISA STIG Cisco IOS Router NDM v3r2
CISC-ND-000550 - The Cisco switch must be configured to enforce a minimum 15-character password length.CiscoDISA STIG Cisco IOS XE Switch NDM v3r2
CISC-ND-000550 - The Cisco switch must be configured to enforce a minimum 15-character password length.CiscoDISA STIG Cisco IOS Switch NDM v3r2
CISC-ND-000570 - The Cisco switch must be configured to enforce password complexity by requiring that at least one uppercase character be used.CiscoDISA STIG Cisco NX-OS Switch NDM v3r2
CISC-ND-000580 - The Cisco switch must be configured to enforce password complexity by requiring that at least one lower-case character be used.CiscoDISA STIG Cisco NX-OS Switch NDM v3r2
CISC-ND-000590 - The Cisco switch must be configured to enforce password complexity by requiring that at least one numeric character be used.CiscoDISA STIG Cisco NX-OS Switch NDM v3r2
CISC-ND-000600 - The Cisco switch must be configured to enforce password complexity by requiring that at least one special character be used.CiscoDISA STIG Cisco NX-OS Switch NDM v3r2
JUEX-NM-000270 - The Juniper EX switch must be configured to enforce a minimum 15-character password length.JuniperDISA Juniper EX Series Network Device Management v2r2
JUEX-NM-000280 - The Juniper EX switch must be configured to enforce password complexity by requiring that at least one uppercase character be used.JuniperDISA Juniper EX Series Network Device Management v2r2
JUEX-NM-000290 - The Juniper EX switch must be configured to enforce password complexity by requiring that at least one lowercase character be used.JuniperDISA Juniper EX Series Network Device Management v2r2
JUEX-NM-000300 - The Juniper EX switch must be configured to enforce password complexity by requiring that at least one numeric character be used.JuniperDISA Juniper EX Series Network Device Management v2r2
JUEX-NM-000310 - The Juniper EX switch must be configured to enforce password complexity by requiring that at least one punctuation (special) character be used.JuniperDISA Juniper EX Series Network Device Management v2r2
JUNI-ND-000550 - The Juniper router must be configured to enforce a minimum 15-character password length.JuniperDISA STIG Juniper Router NDM v3r1
JUNI-ND-000570 - The Juniper router must be configured to enforce password complexity by requiring that at least one uppercase character be used.JuniperDISA STIG Juniper Router NDM v3r1
JUNI-ND-000580 - The Juniper router must be configured to enforce password complexity by requiring that at least one lowercase character be used.JuniperDISA STIG Juniper Router NDM v3r1
JUNI-ND-000590 - The Juniper router must be configured to enforce password complexity by requiring that at least one numeric character be used.JuniperDISA STIG Juniper Router NDM v3r1
JUNI-ND-000600 - The Juniper router must be configured to enforce password complexity by requiring that at least one special character be used.JuniperDISA STIG Juniper Router NDM v3r1
JUSX-DM-000129 - For local accounts using password authentication (i.e., the root account and the account of last resort), the Juniper SRX Services Gateway must enforce password complexity by setting the password change type to character sets.JuniperDISA Juniper SRX Services Gateway NDM v3r2
JUSX-DM-000132 - For local accounts using password authentication (i.e., the root account and the account of last resort), the Juniper SRX Services Gateway must enforce password complexity by requiring at least one numeric character be used.JuniperDISA Juniper SRX Services Gateway NDM v3r2
JUSX-DM-000133 - For local accounts using password authentication (i.e., the root account and the account of last resort), the Juniper SRX Services Gateway must enforce password complexity by requiring at least one special character be used.JuniperDISA Juniper SRX Services Gateway NDM v3r2
MADB-10-003750 - If MariaDB authentication using passwords is employed, MariaDB must enforce the DOD standards for password lifetime.MySQLDBDISA MariaDB Enterprise 10.x v2r2 DB
O121-C2-014900 - Procedures for establishing temporary passwords that meet DOD password requirements for new accounts must be defined, documented, and implemented.OracleDBDISA STIG Oracle 12c v3r2 Database