STIGhubSTIGhub
STIGsRMF ControlsCompare

STIGhub

A free tool to search and browse the entire DISA STIG library. Saves up to 75% in security compliance research time.

Navigation

  • Browse STIGs
  • Search
  • RMF Controls
  • Compare Versions

Resources

  • About
  • Release Notes
  • VPAT
  • DISA STIG Library
STIGs updated 2 hours ago
Powered by Pylon
© 2026 Beacon Cloud Solutions, Inc. All rights reserved.
← IA-5 (1) — Authenticator Management

CCI-000198

Definition

The information system enforces minimum password lifetime restrictions.

Parent Control

IA-5 (1)Authenticator ManagementIdentification and Authentication

Linked STIG Checks (55)

V-222544CAT IIThe application must enforce 24 hours/1 day as the minimum password lifetime.Application Security and Development Security Technical Implementation GuideV-237321CAT IThe ArcGIS Server must use Windows authentication for supporting account management functions.ArcGIS for Server 10.3 Security Technical Implementation GuideV-272627CAT IIICylanceON-PREM must be configured to use a third-party identity provider.Arctic Wolf CylanceON-PREM Security Technical Implementation GuideV-256842CAT IICompliance Guardian must provide automated mechanisms for supporting account management functions.AvePoint Compliance Guardian Security Technical Implementation GuideV-219178CAT IIIThe Ubuntu operating system must enforce 24 hours/1 day as the minimum password lifetime. Passwords for new users must have a 24 hours/1 day minimum password lifetime restriction.Canonical Ubuntu 18.04 LTS Security Technical Implementation GuideV-238202CAT IIIThe Ubuntu operating system must enforce 24 hours/1 day as the minimum password lifetime. Passwords for new users must have a 24 hours/1 day minimum password lifetime restriction.Canonical Ubuntu 20.04 LTS Security Technical Implementation GuideV-260545CAT IIUbuntu 22.04 LTS must enforce 24 hours/one day as the minimum password lifetime. Passwords for new users must have a 24 hours/one day minimum password lifetime restriction.Canonical Ubuntu 22.04 LTS Security Technical Implementation GuideV-269407CAT IIPasswords for existing users must have a 24-hour minimum password lifetime restriction in /etc/shadow.Cloud Linux AlmaLinux OS 9 Security Technical Implementation GuideV-269408CAT IIPasswords for new users or password changes must have a 24-hour minimum password lifetime restriction in /etc/login.defs.Cloud Linux AlmaLinux OS 9 Security Technical Implementation GuideV-255558CAT IIThe DBN-6300 must enforce 24 hours/1 day as the minimum password lifetime.DBN-6300 NDM Security Technical Implementation GuideV-270910CAT IIDragos Platform must use an Identity Provider (IDP) for authentication and authorization processes.Dragos Platform 2.x Security Technical Implementation GuideV-228990CAT IIThe BIG-IP appliance must be configured to enforce 24 hours/1 day as the minimum password lifetime.F5 BIG-IP Device Management Security Technical Implementation GuideV-230168CAT IIThe HP FlexFabric Switch must enforce 24 hours/1 day as the minimum password lifetime.HP FlexFabric Switch NDM Security Technical Implementation GuideV-215222CAT IIAIX Operating systems must enforce 24 hours/1 day as the minimum password lifetime.IBM AIX 7.x Security Technical Implementation GuideV-237914CAT IIIBM zVM CA VM:Secure product PASSWORD user exit must be in use.IBM zVM Using CA VM:Secure Security Technical Implementation GuideV-213895CAT IIIf SQL Server authentication, using passwords, is employed, SQL Server must enforce the DoD standards for password lifetime.MS SQL Server 2014 Instance Security Technical Implementation GuideV-220744CAT IIThe minimum password age must be configured to at least 1 day.Microsoft Windows 10 Security Technical Implementation GuideV-253302CAT IIThe minimum password age must be configured to at least 1 day.Microsoft Windows 11 Security Technical Implementation GuideV-224871CAT IIWindows Server 2016 minimum password age must be configured to at least one day.Microsoft Windows Server 2016 Security Technical Implementation GuideV-205656CAT IIWindows Server 2019 minimum password age must be configured to at least one day.Microsoft Windows Server 2019 Security Technical Implementation GuideV-254290CAT IIWindows Server 2022 minimum password age must be configured to at least one day.Microsoft Windows Server 2022 Security Technical Implementation GuideV-254218CAT IINutanix AOS must enforce 24 hours/1 day as the minimum password lifetime.Nutanix AOS 5.20.x OS Security Technical Implementation GuideV-221681CAT IIThe Oracle Linux operating system must be configured so that passwords for new users are restricted to a 24 hours/1 day minimum lifetime.Oracle Linux 7 Security Technical Implementation GuideV-221682CAT IIThe Oracle Linux operating system must be configured so that passwords are restricted to a 24 hours/1 day minimum lifetime.Oracle Linux 7 Security Technical Implementation GuideV-248694CAT IIOL 8 passwords for new users or password changes must have a 24 hours/one day minimum password lifetime restriction in "/etc/shadow".Oracle Linux 8 Security Technical Implementation GuideV-248695CAT IIOL 8 passwords for new users or password changes must have a 24 hours/one day minimum password lifetime restriction in "/etc/login.defs".Oracle Linux 8 Security Technical Implementation GuideV-253523CAT IIAccess to Prisma Cloud Compute must be managed based on user need and least privileged using external identity providers for authentication and grouping to role-based assignments when possible.Palo Alto Networks Prisma Cloud Compute Security Technical Implementation GuideV-252843CAT IRancher MCM must use a centralized user management solution to support account management functions. For accounts using password authentication, the container platform must use FIPS-validated SHA-2 or later protocol to protect the integrity of the password authentication process.Rancher Government Solutions Multi-Cluster Manager Security Technical Implementation GuideV-204418CAT IIThe Red Hat Enterprise Linux operating system must be configured so that passwords for new users are restricted to a 24 hours/1 day minimum lifetime.Red Hat Enterprise Linux 7 Security Technical Implementation GuideV-204419CAT IIThe Red Hat Enterprise Linux operating system must be configured so that passwords are restricted to a 24 hours/1 day minimum lifetime.Red Hat Enterprise Linux 7 Security Technical Implementation GuideV-230364CAT IIRHEL 8 passwords must have a 24 hours/1 day minimum password lifetime restriction in /etc/shadow.Red Hat Enterprise Linux 8 Security Technical Implementation GuideV-230365CAT IIRHEL 8 passwords for new users or password changes must have a 24 hours/1 day minimum password lifetime restriction in /etc/login.defs.Red Hat Enterprise Linux 8 Security Technical Implementation GuideV-258104CAT IIRHEL 9 passwords for new users or password changes must have a 24 hours minimum password lifetime restriction in /etc/login.defs.Red Hat Enterprise Linux 9 Security Technical Implementation GuideV-258105CAT IIRHEL 9 passwords must have a 24 hours minimum password lifetime restriction in /etc/shadow.Red Hat Enterprise Linux 9 Security Technical Implementation GuideV-257543CAT IOpenShift must use FIPS validated LDAP or OpenIDConnect.Red Hat OpenShift Container Platform 4.x Security Technical Implementation GuideV-254093CAT IInnoslate must use multifactor authentication for network access to privileged and non-privileged accounts.SPEC Innovations Innoslate 4.x Security Technical Implementation GuideV-261388CAT IISLEM 5 must employ user passwords with a minimum lifetime of 24 hours (one day).SUSE Linux Enterprise Micro (SLEM) 5 Security Technical Implementation GuideV-261394CAT IISLEM 5 must be configured to create or update passwords with a minimum lifetime of 24 hours (one day).SUSE Linux Enterprise Micro (SLEM) 5 Security Technical Implementation GuideV-217128CAT IIThe SUSE operating system must be configured to create or update passwords with a minimum lifetime of 24 hours (one day).SUSE Linux Enterprise Server 12 Security Technical Implementation GuideV-217129CAT IIThe SUSE operating system must employ user passwords with a minimum lifetime of 24 hours (one day).SUSE Linux Enterprise Server 12 Security Technical Implementation GuideV-1032CAT IIUsers must not be able to change passwords more than once every 24 hours.SUSE Linux Enterprise Server v11 for System z Security Technical Implementation GuideV-216323CAT IIThe operating system must enforce minimum password lifetime restrictions.Solaris 11 SPARC Security Technical Implementation GuideV-216088CAT IIThe operating system must enforce minimum password lifetime restrictions.Solaris 11 X86 Security Technical Implementation GuideV-254912CAT IITanium must enforce 24 hours/one day as the minimum password lifetime.Tanium 7.x Application on TanOS Security Technical Implementation GuideV-254843CAT IIThe Tanium Operating System (TanOS) must enforce 24 hours/one day as the maximum password lifetime.Tanium 7.x Operating System on TanOS Security Technical Implementation GuideV-253066CAT IITOSS must enforce 24 hours/one day as the minimum password lifetime.Tri-Lab Operating System Stack (TOSS) 4 Security Technical Implementation GuideV-240400CAT IISLES for vRealize must enforce 24 hours/1 day as the minimum password lifetime.VMware vRealize Automation 7.x SLES Security Technical Implementation GuideV-240401CAT IIUsers must not be able to change passwords more than once every 24 hours.VMware vRealize Automation 7.x SLES Security Technical Implementation GuideV-239497CAT IISLES for vRealize must enforce 24 hours/1 day as the minimum password lifetime.VMware vRealize Operations Manager 6.x SLES Security Technical Implementation GuideV-239498CAT IIUsers must not be able to change passwords more than once every 24 hours.VMware vRealize Operations Manager 6.x SLES Security Technical Implementation GuideV-256504CAT IIThe Photon operating system must be configured so that passwords for new users are restricted to a 24-hour minimum lifetime.VMware vSphere 7.0 vCenter Appliance Photon OS Security Technical Implementation GuideV-258820CAT IIThe Photon operating system must enforce one day as the minimum password lifetime.VMware vSphere 8.0 vCenter Appliance Photon OS 4.0 Security Technical Implementation GuideV-73319CAT IIWindows Server 2016 minimum password age must be configured to at least one day.Windows Server 2016 Security Technical Implementation GuideV-73319CAT IIWindows Server 2016 minimum password age must be configured to at least one day.Windows Server 2016 Security Technical Implementation GuideV-93471CAT IIWindows Server 2019 minimum password age must be configured to at least one day.Windows Server 2019 Security Technical Implementation Guide