STIGhubSTIGhub
STIGsRMF ControlsCompare

STIGhub

A free tool to search and browse the entire DISA STIG library. Saves up to 75% in security compliance research time.

Navigation

  • Browse STIGs
  • Search
  • RMF Controls
  • Compare Versions

Resources

  • About
  • Release Notes
  • VPAT
  • DISA STIG Library
STIGs updated 2 hours ago
Powered by Pylon
© 2026 Beacon Cloud Solutions, Inc. All rights reserved.
← IA-5 (1) — Authenticator Management

CCI-000199

Definition

The information system enforces maximum password lifetime restrictions.

Parent Control

IA-5 (1)Authenticator ManagementIdentification and Authentication

Linked STIG Checks (90)

V-76495CAT IIThe Akamai Luna Portal must enforce a 60-day maximum password lifetime restriction.Akamai KSD Service Impact Level 2 NDM Security Technical Implementation GuideV-252521CAT IIThe macOS system must enforce a 60-day maximum password lifetime restriction.Apple macOS 12 (Monterey) Security Technical Implementation GuideV-257227CAT IIThe macOS system must enforce a 60-day maximum password lifetime restriction.Apple macOS 13 (Ventura) Security Technical Implementation GuideV-222545CAT IIThe application must enforce a 60-day maximum password lifetime restriction.Application Security and Development Security Technical Implementation GuideV-237321CAT IThe ArcGIS Server must use Windows authentication for supporting account management functions.ArcGIS for Server 10.3 Security Technical Implementation GuideV-256842CAT IICompliance Guardian must provide automated mechanisms for supporting account management functions.AvePoint Compliance Guardian Security Technical Implementation GuideV-38710CAT IIIBlackBerry PlayBook OS must enforce a maximum lifetime of 120 days for the device unlock password (password age).BlackBerry PlayBook OS V2.1 Security Technical Implementation GuideV-219179CAT IIIThe Ubuntu operating system must enforce a 60-day maximum password lifetime restriction. Passwords for new users must have a 60-day maximum password lifetime restriction.Canonical Ubuntu 18.04 LTS Security Technical Implementation GuideV-238203CAT IIIThe Ubuntu operating system must enforce a 60-day maximum password lifetime restriction. Passwords for new users must have a 60-day maximum password lifetime restriction.Canonical Ubuntu 20.04 LTS Security Technical Implementation GuideV-260546CAT IIUbuntu 22.04 LTS must enforce a 60-day maximum password lifetime restriction. Passwords for new users must have a 60-day maximum password lifetime restriction.Canonical Ubuntu 22.04 LTS Security Technical Implementation GuideV-269405CAT IIPasswords for existing users must have a 60-day maximum password lifetime restriction in /etc/shadow.Cloud Linux AlmaLinux OS 9 Security Technical Implementation GuideV-269406CAT IIPasswords for new users or password changes must have a 60-day maximum password lifetime restriction in /etc/login.defs.Cloud Linux AlmaLinux OS 9 Security Technical Implementation GuideV-255559CAT IIThe DBN-6300 must enforce a 60-day maximum password lifetime restriction.DBN-6300 NDM Security Technical Implementation GuideV-270955CAT IIThe Dragos Platform must configure local password policies.Dragos Platform 2.x Security Technical Implementation GuideV-228991CAT IIThe BIG-IP appliance must be configured to enforce a 60-day maximum password lifetime restriction.F5 BIG-IP Device Management Security Technical Implementation GuideV-255648CAT IICounterACT must enforce a 60-day maximum password lifetime restriction.ForeScout CounterACT NDM Security Technical Implementation GuideV-230169CAT IIThe HP FlexFabric Switch must enforce a 60-day maximum password lifetime restriction.HP FlexFabric Switch NDM Security Technical Implementation GuideV-215223CAT IIAIX Operating systems must enforce a 60-day maximum password lifetime restriction.IBM AIX 7.x Security Technical Implementation GuideV-252568CAT IIIBM Aspera Console user account passwords must have a 60-day maximum password lifetime restriction.IBM Aspera Platform 4.2 Security Technical Implementation GuideV-252586CAT IIIBM Aspera Faspex user account passwords must have a 60-day maximum password lifetime restriction.IBM Aspera Platform 4.2 Security Technical Implementation GuideV-252603CAT IIIBM Aspera Shares user account passwords must have a 60-day maximum password lifetime restriction.IBM Aspera Platform 4.2 Security Technical Implementation GuideV-24358CAT IIThe PASSWORD expiration day(s) value must be set to equal or less then 60 days.IBM Hardware Management Console (HMC) STIGV-255745CAT IIAuthorization for access to the MQ Appliance network device must enforce a 60-day maximum password lifetime restriction.IBM MQ Appliance v9.0 NDM Security Technical Implementation GuideV-237912CAT IICA VM:Secure product AUTOEXP record in the Security Config File must be properly set.IBM zVM Using CA VM:Secure Security Technical Implementation GuideV-213895CAT IIIf SQL Server authentication, using passwords, is employed, SQL Server must enforce the DoD standards for password lifetime.MS SQL Server 2014 Instance Security Technical Implementation GuideV-74197CAT IIThe requirement for scheduled Solidcore client Command Line Interface (CLI) Access Password changes must be documented in the organizations written policy.McAfee Application Control 7.x Security Technical Implementation GuideV-220716CAT IIAccounts must be configured to require password expiration.Microsoft Windows 10 Security Technical Implementation GuideV-220743CAT IIThe maximum password age must be configured to 60 days or less.Microsoft Windows 10 Security Technical Implementation GuideV-220952CAT IIPasswords for enabled local Administrator accounts must be changed at least every 60 days.Microsoft Windows 10 Security Technical Implementation GuideV-253273CAT IIAccounts must be configured to require password expiration.Microsoft Windows 11 Security Technical Implementation GuideV-253301CAT IIThe maximum password age must be configured to 60 days or less.Microsoft Windows 11 Security Technical Implementation GuideV-253476CAT IIPasswords for enabled local Administrator accounts must be changed at least every 60 days.Microsoft Windows 11 Security Technical Implementation GuideV-224820CAT IIPasswords for the built-in Administrator account must be changed at least every 60 days.Microsoft Windows Server 2016 Security Technical Implementation GuideV-224839CAT IIPasswords must be configured to expire.Microsoft Windows Server 2016 Security Technical Implementation GuideV-224870CAT IIWindows Server 2016 maximum password age must be configured to 60 days or less.Microsoft Windows Server 2016 Security Technical Implementation GuideV-205657CAT IIWindows Server 2019 passwords for the built-in Administrator account must be changed at least every 60 days.Microsoft Windows Server 2019 Security Technical Implementation GuideV-205658CAT IIWindows Server 2019 passwords must be configured to expire.Microsoft Windows Server 2019 Security Technical Implementation GuideV-205659CAT IIWindows Server 2019 maximum password age must be configured to 60 days or less.Microsoft Windows Server 2019 Security Technical Implementation GuideV-254239CAT IIWindows Server 2022 passwords for the built-in Administrator account must be changed at least every 60 days.Microsoft Windows Server 2022 Security Technical Implementation GuideV-254258CAT IIWindows Server 2022 passwords must be configured to expire.Microsoft Windows Server 2022 Security Technical Implementation GuideV-254289CAT IIWindows Server 2022 maximum password age must be configured to 60 days or less.Microsoft Windows Server 2022 Security Technical Implementation GuideV-254219CAT IINutanix AOS must enforce a 60-day maximum password lifetime restriction.Nutanix AOS 5.20.x OS Security Technical Implementation GuideV-237733CAT IIProcedures for establishing temporary passwords that meet DoD password requirements for new accounts must be defined, documented, and implemented.Oracle Database 12c Security Technical Implementation GuideV-237735CAT IIThe DBMS must enforce password maximum lifetime restrictions.Oracle Database 12c Security Technical Implementation GuideV-221683CAT IIThe Oracle Linux operating system must be configured so that passwords for new users are restricted to a 60-day maximum lifetime.Oracle Linux 7 Security Technical Implementation GuideV-221684CAT IIThe Oracle Linux operating system must be configured so that existing passwords are restricted to a 60-day maximum lifetime.Oracle Linux 7 Security Technical Implementation GuideV-248696CAT IIOL 8 user account passwords must have a 60-day maximum password lifetime restriction.Oracle Linux 8 Security Technical Implementation GuideV-248697CAT IIOL 8 user account passwords must be configured so that existing passwords are restricted to a 60-day maximum lifetime.Oracle Linux 8 Security Technical Implementation GuideV-253523CAT IIAccess to Prisma Cloud Compute must be managed based on user need and least privileged using external identity providers for authentication and grouping to role-based assignments when possible.Palo Alto Networks Prisma Cloud Compute Security Technical Implementation GuideV-252843CAT IRancher MCM must use a centralized user management solution to support account management functions. For accounts using password authentication, the container platform must use FIPS-validated SHA-2 or later protocol to protect the integrity of the password authentication process.Rancher Government Solutions Multi-Cluster Manager Security Technical Implementation GuideV-204420CAT IIThe Red Hat Enterprise Linux operating system must be configured so that passwords for new users are restricted to a 60-day maximum lifetime.Red Hat Enterprise Linux 7 Security Technical Implementation GuideV-204421CAT IIThe Red Hat Enterprise Linux operating system must be configured so that existing passwords are restricted to a 60-day maximum lifetime.Red Hat Enterprise Linux 7 Security Technical Implementation GuideV-230366CAT IIRHEL 8 user account passwords must have a 60-day maximum password lifetime restriction.Red Hat Enterprise Linux 8 Security Technical Implementation GuideV-230367CAT IIRHEL 8 user account passwords must be configured so that existing passwords are restricted to a 60-day maximum lifetime.Red Hat Enterprise Linux 8 Security Technical Implementation GuideV-258041CAT IIRHEL 9 user account passwords for new users or password changes must have a 60-day maximum password lifetime restriction in /etc/login.defs.Red Hat Enterprise Linux 9 Security Technical Implementation GuideV-258042CAT IIRHEL 9 user account passwords must have a 60-day maximum password lifetime restriction.Red Hat Enterprise Linux 9 Security Technical Implementation GuideV-257543CAT IOpenShift must use FIPS validated LDAP or OpenIDConnect.Red Hat OpenShift Container Platform 4.x Security Technical Implementation GuideV-254093CAT IInnoslate must use multifactor authentication for network access to privileged and non-privileged accounts.SPEC Innovations Innoslate 4.x Security Technical Implementation GuideV-261389CAT IISLEM 5 must employ user passwords with a maximum lifetime of 60 days.SUSE Linux Enterprise Micro (SLEM) 5 Security Technical Implementation GuideV-261395CAT IISLEM 5 must be configured to create or update passwords with a maximum lifetime of 60 days.SUSE Linux Enterprise Micro (SLEM) 5 Security Technical Implementation GuideV-217130CAT IIThe SUSE operating system must be configured to create or update passwords with a maximum lifetime of 60 days.SUSE Linux Enterprise Server 12 Security Technical Implementation GuideV-217131CAT IIThe SUSE operating system must employ user passwords with a maximum lifetime of 60 days.SUSE Linux Enterprise Server 12 Security Technical Implementation GuideV-11977CAT IIAll non-interactive/automated processing account passwords must be changed at least once per year or be locked.SUSE Linux Enterprise Server v11 for System z Security Technical Implementation GuideV-216321CAT IIUser passwords must be changed at least every 60 days.Solaris 11 SPARC Security Technical Implementation GuideV-216086CAT IIUser passwords must be changed at least every 60 days.Solaris 11 X86 Security Technical Implementation GuideV-221634CAT IIISplunk Enterprise must enforce a 60-day maximum password lifetime restriction for the account of last resort.Splunk Enterprise 7.x for Windows Security Technical Implementation GuideV-251687CAT IIISplunk Enterprise must be configured to enforce a 60-day maximum password lifetime restriction.Splunk Enterprise 8.x for Linux Security Technical Implementation GuideV-254913CAT IIThe Tanium application must enforce a 60-day maximum password lifetime restriction.Tanium 7.x Application on TanOS Security Technical Implementation GuideV-254844CAT IIThe Tanium Operating System (TanOS) must enforce a 60-day maximum password lifetime restriction.Tanium 7.x Operating System on TanOS Security Technical Implementation GuideV-213320CAT IIThe requirement for scheduled Solidcore client Command Line Interface (CLI) Access Password changes must be documented in the organizations written policy.Trellix Application Control 8.x Security Technical Implementation GuideV-241139CAT IITrend Deep Security must enforce a 60-day maximum password lifetime restriction.Trend Micro Deep Security 9.x Security Technical Implementation GuideV-253067CAT IITOSS must enforce a 60-day maximum password lifetime restriction.Tri-Lab Operating System Stack (TOSS) 4 Security Technical Implementation GuideV-69187CAT IIThe NSX vCenter must enforce a 60-day maximum password lifetime restriction.VMware NSX Manager Security Technical Implementation GuideV-240402CAT IISLES for vRealize must enforce a 60-day maximum password lifetime restriction.VMware vRealize Automation 7.x SLES Security Technical Implementation GuideV-240403CAT IIUser passwords must be changed at least every 60 days.VMware vRealize Automation 7.x SLES Security Technical Implementation GuideV-239499CAT IISLES for vRealize must enforce a 60-day maximum password lifetime restriction.VMware vRealize Operations Manager 6.x SLES Security Technical Implementation GuideV-239500CAT IIUser passwords must be changed at least every 60 days.VMware vRealize Operations Manager 6.x SLES Security Technical Implementation GuideV-256505CAT IIThe Photon operating system must be configured so that passwords for new users are restricted to a 90-day maximum lifetime.VMware vSphere 7.0 vCenter Appliance Photon OS Security Technical Implementation GuideV-256332CAT IIThe vCenter Server must enforce a 60-day maximum password lifetime restriction.VMware vSphere 7.0 vCenter Security Technical Implementation GuideV-258821CAT IIThe Photon operating systems must enforce a 90-day maximum password lifetime restriction.VMware vSphere 8.0 vCenter Appliance Photon OS 4.0 Security Technical Implementation GuideV-258918CAT IIThe vCenter Server must enforce a 90-day maximum password lifetime restriction.VMware vSphere 8.0 vCenter Security Technical Implementation GuideV-73223CAT IIPasswords for the built-in Administrator account must be changed at least every 60 days.Windows Server 2016 Security Technical Implementation GuideV-73223CAT IIPasswords for the built-in Administrator account must be changed at least every 60 days.Windows Server 2016 Security Technical Implementation GuideV-73263CAT IIPasswords must be configured to expire.Windows Server 2016 Security Technical Implementation GuideV-73263CAT IIPasswords must be configured to expire.Windows Server 2016 Security Technical Implementation GuideV-73317CAT IIWindows Server 2016 maximum password age must be configured to 60 days or less.Windows Server 2016 Security Technical Implementation GuideV-73317CAT IIWindows Server 2016 maximum password age must be configured to 60 days or less.Windows Server 2016 Security Technical Implementation GuideV-93473CAT IIWindows Server 2019 passwords for the built-in Administrator account must be changed at least every 60 days.Windows Server 2019 Security Technical Implementation GuideV-93475CAT IIWindows Server 2019 passwords must be configured to expire.Windows Server 2019 Security Technical Implementation GuideV-93477CAT IIWindows Server 2019 maximum password age must be configured to 60 days or less.Windows Server 2019 Security Technical Implementation Guide