STIGhub
STIGs
RMF Controls
Compare
← IA-5 (1) — Authenticator Management
CCI-004066
Definition
For password-based authentication, enforce organization-defined composition and complexity rules.
Parent Control
IA-5 (1)
Authenticator Management
Identification and Authentication
Linked STIG Checks (200)
V-204664
CAT II
AAA Services must be configured to enforce a minimum 15-character password length.
AAA Services Security Requirements Guide
V-204666
CAT II
AAA Services must be configured to enforce password complexity by requiring that at least one uppercase character be used.
AAA Services Security Requirements Guide
V-204667
CAT II
AAA Services must be configured to enforce password complexity by requiring that at least one lowercase character be used.
AAA Services Security Requirements Guide
V-204668
CAT II
AAA Services must be configured to enforce password complexity by requiring that at least one numeric character be used.
AAA Services Security Requirements Guide
V-204669
CAT II
AAA Services must be configured to enforce password complexity by requiring that at least one special character be used.
AAA Services Security Requirements Guide
V-204670
CAT II
AAA Services must be configured to require the change of at least eight of the total number of characters when passwords are changed.
AAA Services Security Requirements Guide
V-204673
CAT II
AAA Services must be configured to enforce 24 hours as the minimum password lifetime.
AAA Services Security Requirements Guide
V-204674
CAT II
AAA Services must be configured to enforce a 60-day maximum password lifetime restriction.
AAA Services Security Requirements Guide
V-274133
CAT II
Amazon Linux 2023 must enforce password complexity by requiring that at least one uppercase character be used.
Amazon Linux 2023 Security Technical Implementation Guide
V-274134
CAT II
Amazon Linux 2023 must enforce password complexity by requiring that at least one lowercase character be used.
Amazon Linux 2023 Security Technical Implementation Guide
V-274135
CAT II
Amazon Linux 2023 must enforce password complexity by requiring that at least one numeric character be used.
Amazon Linux 2023 Security Technical Implementation Guide
V-274136
CAT II
Amazon Linux 2023 must require the change of at least 50 percent of the total number of characters when passwords are changed.
Amazon Linux 2023 Security Technical Implementation Guide
V-274137
CAT II
Amazon Linux 2023 must enforce a minimum 15-character password length.
Amazon Linux 2023 Security Technical Implementation Guide
V-274138
CAT II
Amazon Linux 2023 must enforce password complexity by requiring that at least one special character be used.
Amazon Linux 2023 Security Technical Implementation Guide
V-274139
CAT II
Amazon Linux 2023 must enforce password complexity rules for the root account.
Amazon Linux 2023 Security Technical Implementation Guide
V-274143
CAT II
Amazon Linux 2023 must enforce 24 hours/1 day as the minimum password lifetime.
Amazon Linux 2023 Security Technical Implementation Guide
V-274148
CAT II
Amazon Linux 2023 must be able to enforce a 60-day maximum password lifetime restriction.
Amazon Linux 2023 Security Technical Implementation Guide
V-274161
CAT II
Amazon Linux 2023 must ensure the password complexity module is enabled in the password-auth file.
Amazon Linux 2023 Security Technical Implementation Guide
V-268126
CAT II
NixOS must enforce password complexity by requiring that at least one uppercase character be used.
Anduril NixOS Security Technical Implementation Guide
V-268127
CAT II
NixOS must enforce password complexity by requiring that at least one lowercase character be used.
Anduril NixOS Security Technical Implementation Guide
V-268128
CAT II
NixOS must enforce password complexity by requiring that at least one numeric character be used.
Anduril NixOS Security Technical Implementation Guide
V-268129
CAT II
NixOS must require the change of at least 50 percent of the total number of characters when passwords are changed.
Anduril NixOS Security Technical Implementation Guide
V-268132
CAT II
NixOS must enforce 24 hours/one day as the minimum password lifetime.
Anduril NixOS Security Technical Implementation Guide
V-268133
CAT II
NixOS must enforce a 60-day maximum password lifetime restriction.
Anduril NixOS Security Technical Implementation Guide
V-268134
CAT II
NixOS must enforce a minimum 15-character password length.
Anduril NixOS Security Technical Implementation Guide
V-268145
CAT II
NixOS must enforce password complexity by requiring that at least one special character be used.
Anduril NixOS Security Technical Implementation Guide
V-254588
CAT II
Apple iOS/iPadOS 16 must be configured to enforce a minimum password length of six characters.
Apple iOS-iPadOS 16 Security Technical Implementation Guide
V-258320
CAT II
Apple iOS/iPadOS 17 must be configured to enforce a minimum password length of six characters.
Apple iOS/iPadOS 17 Security Technical Implementation Guide
V-258321
CAT II
Apple iOS/iPadOS 17 must be configured to not allow passwords that include more than four repeating or sequential characters.
Apple iOS/iPadOS 17 Security Technical Implementation Guide
V-267987
CAT II
Apple iOS/iPadOS 18 must be configured to enforce a minimum password length of six characters.
Apple iOS/iPadOS 18 Security Technical Implementation Guide
V-267988
CAT II
Apple iOS/iPadOS 18 must be configured to not allow passwords that include more than four repeating or sequential characters.
Apple iOS/iPadOS 18 Security Technical Implementation Guide
V-278747
CAT II
Apple iOS/iPadOS 26 must be configured to enforce a minimum password length of six characters.
Apple iOS/iPadOS 26 Security Technical Implementation Guide
V-278748
CAT II
Apple iOS/iPadOS 26 must be configured to not allow passwords that include more than four repeating or sequential characters.
Apple iOS/iPadOS 26 Security Technical Implementation Guide
V-259537
CAT II
The macOS system must require passwords contain a minimum of one numeric character.
Apple macOS 14 (Sonoma) Security Technical Implementation Guide
V-259538
CAT II
The macOS system must restrict maximum password lifetime to 60 days.
Apple macOS 14 (Sonoma) Security Technical Implementation Guide
V-259540
CAT II
The macOS system must require a minimum password length of 14 characters.
Apple macOS 14 (Sonoma) Security Technical Implementation Guide
V-259541
CAT II
The macOS system must require passwords contain a minimum of one special character.
Apple macOS 14 (Sonoma) Security Technical Implementation Guide
V-259550
CAT II
The macOS system must require passwords contain a minimum of one lowercase character and one uppercase character.
Apple macOS 14 (Sonoma) Security Technical Implementation Guide
V-259551
CAT II
The macOS system must set minimum password lifetime to 24 hours.
Apple macOS 14 (Sonoma) Security Technical Implementation Guide
V-268535
CAT II
The macOS system must require that passwords contain a minimum of one numeric character.
Apple macOS 15 (Sequoia) Security Technical Implementation Guide
V-268536
CAT II
The macOS system must restrict maximum password lifetime to 60 days.
Apple macOS 15 (Sequoia) Security Technical Implementation Guide
V-268537
CAT II
The macOS system must require a minimum password length of 14 characters.
Apple macOS 15 (Sequoia) Security Technical Implementation Guide
V-268538
CAT II
The macOS system must require that passwords contain a minimum of one special character.
Apple macOS 15 (Sequoia) Security Technical Implementation Guide
V-268547
CAT II
The macOS system must require that passwords contain a minimum of one lowercase character and one uppercase character.
Apple macOS 15 (Sequoia) Security Technical Implementation Guide
V-268548
CAT II
The macOS system must set minimum password lifetime to 24 hours.
Apple macOS 15 (Sequoia) Security Technical Implementation Guide
V-277144
CAT II
The macOS system must require that passwords contain a minimum of one numeric character.
Apple macOS 26 (Tahoe) Security Technical Implementation Guide
V-277145
CAT II
The macOS system must restrict maximum password lifetime to 60 days.
Apple macOS 26 (Tahoe) Security Technical Implementation Guide
V-277146
CAT II
The macOS system must require a minimum password length of 14 characters.
Apple macOS 26 (Tahoe) Security Technical Implementation Guide
V-277147
CAT II
The macOS system must require that passwords contain a minimum of one special character.
Apple macOS 26 (Tahoe) Security Technical Implementation Guide
V-277155
CAT II
The macOS system must require that passwords contain a minimum of one lowercase character and one uppercase character.
Apple macOS 26 (Tahoe) Security Technical Implementation Guide
V-277156
CAT II
The macOS system must set minimum password lifetime to 24 hours.
Apple macOS 26 (Tahoe) Security Technical Implementation Guide
V-276380
CAT II
Apple visionOS 2 must be configured to enforce a minimum password length of six characters.
Apple visionOS 2 Security Technical Implementation Guide
V-276381
CAT II
Apple visionOS 2 must be configured to not allow passwords that include more than four repeating or sequential characters.
Apple visionOS 2 Security Technical Implementation Guide
V-282789
CAT II
Apple visionOS 26 must be configured to enforce a minimum password length of six characters.
Apple visionOS 26 Security Technical Implementation Guide
V-282790
CAT II
Apple visionOS 26 must be configured to not allow passwords that include more than four repeating or sequential characters.
Apple visionOS 26 Security Technical Implementation Guide
V-222536
CAT I
The application must enforce a minimum 15-character password length.
Application Security and Development Security Technical Implementation Guide
V-222537
CAT II
The application must enforce password complexity by requiring that at least one uppercase character be used.
Application Security and Development Security Technical Implementation Guide
V-222538
CAT II
The application must enforce password complexity by requiring that at least one lowercase character be used.
Application Security and Development Security Technical Implementation Guide
V-222539
CAT II
The application must enforce password complexity by requiring that at least one numeric character be used.
Application Security and Development Security Technical Implementation Guide
V-222540
CAT II
The application must enforce password complexity by requiring that at least one special character be used.
Application Security and Development Security Technical Implementation Guide
V-222541
CAT II
The application must require the change of at least eight of the total number of characters when passwords are changed.
Application Security and Development Security Technical Implementation Guide
V-222544
CAT II
The application must enforce 24 hours/1 day as the minimum password lifetime.
Application Security and Development Security Technical Implementation Guide
V-222545
CAT II
The application must enforce a 60-day maximum password lifetime restriction.
Application Security and Development Security Technical Implementation Guide
V-272627
CAT III
CylanceON-PREM must be configured to use a third-party identity provider.
Arctic Wolf CylanceON-PREM Security Technical Implementation Guide
V-255954
CAT II
The Arista network device must enforce a minimum 15-character password length.
Arista MLS EOS 4.X NDM Security Technical Implementation Guide
V-276012
CAT I
Ax-OS must have no local accounts for the user interface.
Axonius Federal Systems Ax-OS Security Technical Implementation Guide
V-238202
CAT III
The Ubuntu operating system must enforce 24 hours/1 day as the minimum password lifetime. Passwords for new users must have a 24 hours/1 day minimum password lifetime restriction.
Canonical Ubuntu 20.04 LTS Security Technical Implementation Guide
V-238203
CAT III
The Ubuntu operating system must enforce a 60-day maximum password lifetime restriction. Passwords for new users must have a 60-day maximum password lifetime restriction.
Canonical Ubuntu 20.04 LTS Security Technical Implementation Guide
V-238221
CAT III
The Ubuntu operating system must enforce password complexity by requiring that at least one upper-case character be used.
Canonical Ubuntu 20.04 LTS Security Technical Implementation Guide
V-238222
CAT III
The Ubuntu operating system must enforce password complexity by requiring that at least one lower-case character be used.
Canonical Ubuntu 20.04 LTS Security Technical Implementation Guide
V-238223
CAT III
The Ubuntu operating system must enforce password complexity by requiring that at least one numeric character be used.
Canonical Ubuntu 20.04 LTS Security Technical Implementation Guide
V-238224
CAT III
The Ubuntu operating system must require the change of at least 8 characters when passwords are changed.
Canonical Ubuntu 20.04 LTS Security Technical Implementation Guide
V-238225
CAT II
The Ubuntu operating system must enforce a minimum 15-character password length.
Canonical Ubuntu 20.04 LTS Security Technical Implementation Guide
V-238226
CAT III
The Ubuntu operating system must enforce password complexity by requiring that at least one special character be used.
Canonical Ubuntu 20.04 LTS Security Technical Implementation Guide
V-260545
CAT II
Ubuntu 22.04 LTS must enforce 24 hours/one day as the minimum password lifetime. Passwords for new users must have a 24 hours/one day minimum password lifetime restriction.
Canonical Ubuntu 22.04 LTS Security Technical Implementation Guide
V-260546
CAT II
Ubuntu 22.04 LTS must enforce a 60-day maximum password lifetime restriction. Passwords for new users must have a 60-day maximum password lifetime restriction.
Canonical Ubuntu 22.04 LTS Security Technical Implementation Guide
V-260560
CAT II
Ubuntu 22.04 LTS must enforce password complexity by requiring at least one uppercase character be used.
Canonical Ubuntu 22.04 LTS Security Technical Implementation Guide
V-260561
CAT II
Ubuntu 22.04 LTS must enforce password complexity by requiring at least one lowercase character be used.
Canonical Ubuntu 22.04 LTS Security Technical Implementation Guide
V-260562
CAT II
Ubuntu 22.04 LTS must enforce password complexity by requiring that at least one numeric character be used.
Canonical Ubuntu 22.04 LTS Security Technical Implementation Guide
V-260563
CAT II
Ubuntu 22.04 LTS must enforce password complexity by requiring that at least one special character be used.
Canonical Ubuntu 22.04 LTS Security Technical Implementation Guide
V-260565
CAT II
Ubuntu 22.04 LTS must enforce a minimum 15-character password length.
Canonical Ubuntu 22.04 LTS Security Technical Implementation Guide
V-260566
CAT II
Ubuntu 22.04 LTS must require the change of at least eight characters when passwords are changed.
Canonical Ubuntu 22.04 LTS Security Technical Implementation Guide
V-270726
CAT II
Ubuntu 24.04 LTS must enforce password complexity by requiring that at least one uppercase character be used.
Canonical Ubuntu 24.04 LTS Security Technical Implementation Guide
V-270727
CAT II
Ubuntu 24.04 LTS must enforce password complexity by requiring that at least one lowercase character be used.
Canonical Ubuntu 24.04 LTS Security Technical Implementation Guide
V-270728
CAT II
Ubuntu 24.04 LTS must enforce password complexity by requiring that at least one numeric character be used.
Canonical Ubuntu 24.04 LTS Security Technical Implementation Guide
V-270729
CAT II
Ubuntu 24.04 LTS must require the change of at least eight characters when passwords are changed.
Canonical Ubuntu 24.04 LTS Security Technical Implementation Guide
V-270730
CAT II
Ubuntu 24.04 LTS must enforce 24 hours/1 day as the minimum password lifetime. Passwords for new users must have a 24 hours/1 day minimum password lifetime restriction.
Canonical Ubuntu 24.04 LTS Security Technical Implementation Guide
V-270731
CAT II
Ubuntu 24.04 LTS must enforce a 60-day maximum password lifetime restriction. Passwords for new users must have a 60-day maximum password lifetime restriction.
Canonical Ubuntu 24.04 LTS Security Technical Implementation Guide
V-270732
CAT II
Ubuntu 24.04 LTS must enforce a minimum 15-character password length.
Canonical Ubuntu 24.04 LTS Security Technical Implementation Guide
V-270733
CAT II
Ubuntu 24.04 LTS must enforce password complexity by requiring that at least one special character be used.
Canonical Ubuntu 24.04 LTS Security Technical Implementation Guide
V-206467
CAT II
The Central Log Server must be configured to enforce a minimum 15-character password length.
Central Log Server Security Requirements Guide
V-206469
CAT III
The Central Log Server must be configured to enforce password complexity by requiring that at least one uppercase character be used.
Central Log Server Security Requirements Guide
V-206470
CAT III
The Central Log Server must be configured to enforce password complexity by requiring that at least one lowercase character be used.
Central Log Server Security Requirements Guide
V-206471
CAT III
The Central Log Server must be configured to enforce password complexity by requiring that at least one numeric character be used.
Central Log Server Security Requirements Guide
V-206472
CAT III
The Central Log Server must be configured to enforce password complexity by requiring that at least one special character be used.
Central Log Server Security Requirements Guide
V-206473
CAT III
The Central Log Server must be configured to require the change of at least eight of the total number of characters when passwords are changed.
Central Log Server Security Requirements Guide
V-206476
CAT III
The Central Log Server must be configured to enforce 24 hours/1 day as the minimum password lifetime.
Central Log Server Security Requirements Guide
V-206477
CAT III
The Central Log Server must be configured to enforce a 60-day maximum password lifetime restriction.
Central Log Server Security Requirements Guide
V-271958
CAT II
The Cisco ACI must be configured to allow user selection of long passwords and passphrases, including spaces and all printable characters, for password-based authentication.
Cisco ACI NDM Security Technical Implementation Guide
V-271960
CAT II
The Cisco ACI must enforce a minimum 15-character password length.
Cisco ACI NDM Security Technical Implementation Guide
V-239914
CAT II
The Cisco ASA must be configured to enforce a minimum 15-character password length.
Cisco ASA NDM Security Technical Implementation Guide
V-239915
CAT II
The Cisco ASA must be configured to enforce password complexity by requiring that at least one uppercase character be used.
Cisco ASA NDM Security Technical Implementation Guide
V-239916
CAT II
The Cisco ASA must be configured to enforce password complexity by requiring that at least one lowercase character be used.
Cisco ASA NDM Security Technical Implementation Guide
V-239917
CAT II
The Cisco ASA must be configured to enforce password complexity by requiring that at least one numeric character be used.
Cisco ASA NDM Security Technical Implementation Guide
V-239918
CAT II
The Cisco ASA must be configured to enforce password complexity by requiring that at least one special character be used.
Cisco ASA NDM Security Technical Implementation Guide
V-239919
CAT II
The Cisco ASA must be configured to require that when a password is changed, the characters are changed in at least eight of the positions within the password.
Cisco ASA NDM Security Technical Implementation Guide
V-215681
CAT II
The Cisco router must be configured to enforce a minimum 15-character password length.
Cisco IOS Router NDM Security Technical Implementation Guide
V-215682
CAT II
The Cisco router must be configured to enforce password complexity by requiring that at least one uppercase character be used.
Cisco IOS Router NDM Security Technical Implementation Guide
V-215683
CAT II
The Cisco router must be configured to enforce password complexity by requiring that at least one lowercase character be used.
Cisco IOS Router NDM Security Technical Implementation Guide
V-215684
CAT II
The Cisco router must be configured to enforce password complexity by requiring that at least one numeric character be used.
Cisco IOS Router NDM Security Technical Implementation Guide
V-215685
CAT II
The Cisco router must be configured to enforce password complexity by requiring that at least one special character be used.
Cisco IOS Router NDM Security Technical Implementation Guide
V-215686
CAT II
The Cisco router must be configured to require that when a password is changed, the characters are changed in at least eight of the positions within the password.
Cisco IOS Router NDM Security Technical Implementation Guide
V-220589
CAT II
The Cisco switch must be configured to enforce a minimum 15-character password length.
Cisco IOS Switch NDM Security Technical Implementation Guide
V-220590
CAT II
The Cisco switch must be configured to enforce password complexity by requiring that at least one uppercase character be used.
Cisco IOS Switch NDM Security Technical Implementation Guide
V-220591
CAT II
The Cisco switch must be configured to enforce password complexity by requiring that at least one lowercase character be used.
Cisco IOS Switch NDM Security Technical Implementation Guide
V-220592
CAT II
The Cisco switch must be configured to enforce password complexity by requiring that at least one numeric character be used.
Cisco IOS Switch NDM Security Technical Implementation Guide
V-220593
CAT II
The Cisco switch must be configured to enforce password complexity by requiring that at least one special character be used.
Cisco IOS Switch NDM Security Technical Implementation Guide
V-220594
CAT II
The Cisco switch must be configured to require that when a password is changed, the characters are changed in at least eight of the positions within the password.
Cisco IOS Switch NDM Security Technical Implementation Guide
V-215826
CAT II
The Cisco router must be configured to enforce a minimum 15-character password length.
Cisco IOS XE Router NDM Security Technical Implementation Guide
V-215827
CAT II
The Cisco router must be configured to enforce password complexity by requiring that at least one uppercase character be used.
Cisco IOS XE Router NDM Security Technical Implementation Guide
V-215828
CAT II
The Cisco router must be configured to enforce password complexity by requiring that at least one lowercase character be used.
Cisco IOS XE Router NDM Security Technical Implementation Guide
V-215829
CAT II
The Cisco router must be configured to enforce password complexity by requiring that at least one numeric character be used.
Cisco IOS XE Router NDM Security Technical Implementation Guide
V-215830
CAT II
The Cisco router must be configured to enforce password complexity by requiring that at least one special character be used.
Cisco IOS XE Router NDM Security Technical Implementation Guide
V-215831
CAT II
The Cisco router must be configured to require that when a password is changed, the characters are changed in at least eight of the positions within the password.
Cisco IOS XE Router NDM Security Technical Implementation Guide
V-220537
CAT II
The Cisco switch must be configured to enforce a minimum 15-character password length.
Cisco IOS XE Switch NDM Security Technical Implementation Guide
V-220538
CAT II
The Cisco switch must be configured to enforce password complexity by requiring that at least one uppercase character be used.
Cisco IOS XE Switch NDM Security Technical Implementation Guide
V-220539
CAT II
The Cisco switch must be configured to enforce password complexity by requiring that at least one lowercase character be used.
Cisco IOS XE Switch NDM Security Technical Implementation Guide
V-220540
CAT II
The Cisco switch must be configured to enforce password complexity by requiring that at least one numeric character be used.
Cisco IOS XE Switch NDM Security Technical Implementation Guide
V-220541
CAT II
The Cisco switch must be configured to enforce password complexity by requiring that at least one special character be used.
Cisco IOS XE Switch NDM Security Technical Implementation Guide
V-220542
CAT II
The Cisco switch must be configured to require that when a password is changed, the characters are changed in at least eight of the positions within the password.
Cisco IOS XE Switch NDM Security Technical Implementation Guide
V-242645
CAT II
For accounts using password authentication, the Cisco ISE must enforce a minimum 15-character password length.
Cisco ISE NDM Security Technical Implementation Guide
V-242646
CAT II
For accounts using password authentication, the Cisco ISE must enforce password complexity by requiring that at least one uppercase character be used.
Cisco ISE NDM Security Technical Implementation Guide
V-242647
CAT II
For accounts using password authentication, the Cisco ISE must enforce password complexity by requiring that at least one lowercase character be used.
Cisco ISE NDM Security Technical Implementation Guide
V-242648
CAT II
For accounts using password authentication, the Cisco ISE must enforce password complexity by requiring that at least one digit be used.
Cisco ISE NDM Security Technical Implementation Guide
V-242649
CAT II
For accounts using password authentication, the Cisco ISE must enforce password complexity by requiring that at least one special character be used.
Cisco ISE NDM Security Technical Implementation Guide
V-220489
CAT II
The Cisco switch must be configured to enforce password complexity by requiring that at least one uppercase character be used.
Cisco NX OS Switch NDM Security Technical Implementation Guide
V-220490
CAT II
The Cisco switch must be configured to enforce password complexity by requiring that at least one lower-case character be used.
Cisco NX OS Switch NDM Security Technical Implementation Guide
V-220491
CAT II
The Cisco switch must be configured to enforce password complexity by requiring that at least one numeric character be used.
Cisco NX OS Switch NDM Security Technical Implementation Guide
V-220492
CAT II
The Cisco switch must be configured to enforce password complexity by requiring that at least one special character be used.
Cisco NX OS Switch NDM Security Technical Implementation Guide
V-269385
CAT II
AlmaLinux OS 9 must enforce password complexity by requiring that at least one lowercase character be used.
Cloud Linux AlmaLinux OS 9 Security Technical Implementation Guide
V-269386
CAT II
AlmaLinux OS 9 must ensure the password complexity module is enabled in the password-auth file.
Cloud Linux AlmaLinux OS 9 Security Technical Implementation Guide
V-269387
CAT II
AlmaLinux OS 9 must ensure the password complexity module in the system-auth file is configured for three retries or less.
Cloud Linux AlmaLinux OS 9 Security Technical Implementation Guide
V-269388
CAT II
AlmaLinux OS 9 must enforce password complexity rules for the root account.
Cloud Linux AlmaLinux OS 9 Security Technical Implementation Guide
V-269389
CAT II
AlmaLinux OS 9 must enforce password complexity by requiring that at least one uppercase character be used.
Cloud Linux AlmaLinux OS 9 Security Technical Implementation Guide
V-269390
CAT II
AlmaLinux OS 9 must enforce password complexity by requiring that at least one special character be used.
Cloud Linux AlmaLinux OS 9 Security Technical Implementation Guide
V-269392
CAT II
AlmaLinux OS 9 passwords must be created with a minimum of 15 characters.
Cloud Linux AlmaLinux OS 9 Security Technical Implementation Guide
V-269393
CAT II
AlmaLinux OS 9 must enforce password complexity by requiring that at least one numeric character be used.
Cloud Linux AlmaLinux OS 9 Security Technical Implementation Guide
V-269394
CAT II
AlmaLinux OS 9 must require the change of at least four character classes when passwords are changed.
Cloud Linux AlmaLinux OS 9 Security Technical Implementation Guide
V-269395
CAT II
AlmaLinux OS 9 must require the maximum number of repeating characters be limited to three when passwords are changed.
Cloud Linux AlmaLinux OS 9 Security Technical Implementation Guide
V-269396
CAT II
AlmaLinux OS 9 must require the maximum number of repeating characters of the same character class be limited to four when passwords are changed.
Cloud Linux AlmaLinux OS 9 Security Technical Implementation Guide
V-269397
CAT II
AlmaLinux OS 9 must require the change of at least eight characters when passwords are changed.
Cloud Linux AlmaLinux OS 9 Security Technical Implementation Guide
V-233088
CAT II
The container platform must enforce a minimum 15-character password length.
Container Platform Security Requirements Guide
V-233090
CAT II
The container platform must enforce password complexity by requiring that at least one uppercase character be used.
Container Platform Security Requirements Guide
V-233091
CAT II
The container platform must enforce password complexity by requiring that at least one lowercase character be used.
Container Platform Security Requirements Guide
V-233092
CAT II
The container platform must enforce password complexity by requiring that at least one numeric character be used.
Container Platform Security Requirements Guide
V-233093
CAT II
The container platform must enforce password complexity by requiring that at least one special character be used.
Container Platform Security Requirements Guide
V-233094
CAT II
The container platform must require the change of at least eight of the total number of characters when passwords are changed.
Container Platform Security Requirements Guide
V-233097
CAT II
The container platform must enforce 24 hours (one day) as the minimum password lifetime.
Container Platform Security Requirements Guide
V-233098
CAT II
The container platform must enforce a 60-day maximum password lifetime restriction.
Container Platform Security Requirements Guide
V-206555
CAT I
If DBMS authentication, using passwords, is employed, the DBMS must enforce the DOD standards for password complexity and lifetime.
Database Security Requirements Guide
V-269781
CAT II
The Dell OS10 Switch must enforce a minimum 15-character password length.
Dell OS10 Switch NDM Security Technical Implementation Guide
V-269782
CAT II
The Dell OS10 Switch must enforce password complexity by requiring that at least one uppercase character be used.
Dell OS10 Switch NDM Security Technical Implementation Guide
V-269783
CAT II
The Dell OS10 Switch must enforce password complexity by requiring that at least one lowercase character be used.
Dell OS10 Switch NDM Security Technical Implementation Guide
V-269784
CAT II
The Dell OS10 Switch must enforce password complexity by requiring that at least one numeric character be used.
Dell OS10 Switch NDM Security Technical Implementation Guide
V-269785
CAT II
The Dell OS10 Switch must enforce password complexity by requiring that at least one special character be used.
Dell OS10 Switch NDM Security Technical Implementation Guide
V-263640
CAT II
The DNS server implementation must, for password-based authentication, enforce organization-defined composition and complexity rules.
Domain Name System (DNS) Security Requirements Guide
V-259246
CAT I
If DBMS authentication, using passwords, is employed, EDB Postgres Advanced Server must enforce the DOD standards for password complexity and lifetime.
EnterpriseDB Postgres Advanced Server (EPAS) Security Technical Implementation Guide
V-278408
CAT II
The NGINX service account must be configured to lock changes to the password.
F5 NGINX Security Technical Implementation Guide
V-230963
CAT II
Forescout must enforce password complexity by requiring that at least one uppercase character be used.
Forescout Network Device Management Security Technical Implementation Guide
V-230964
CAT II
Forescout must enforce password complexity by requiring that at least one lowercase character be used.
Forescout Network Device Management Security Technical Implementation Guide
V-230965
CAT II
Forescout must enforce a minimum 15-character password length.
Forescout Network Device Management Security Technical Implementation Guide
V-230966
CAT II
Forescout must enforce password complexity by requiring that at least one numeric character be used.
Forescout Network Device Management Security Technical Implementation Guide
V-230967
CAT II
Forescout must enforce password complexity by requiring that at least one special character be used.
Forescout Network Device Management Security Technical Implementation Guide
V-230968
CAT III
Forescout must require that when a password is changed, the characters are changed in at least eight of the positions within the password.
Forescout Network Device Management Security Technical Implementation Guide
V-203625
CAT II
The operating system must enforce password complexity by requiring that at least one uppercase character be used.
General Purpose Operating System Security Requirements Guide
V-203626
CAT II
The operating system must enforce password complexity by requiring that at least one lowercase character be used.
General Purpose Operating System Security Requirements Guide
V-203627
CAT II
The operating system must enforce password complexity by requiring that at least one numeric character be used.
General Purpose Operating System Security Requirements Guide
V-203628
CAT II
The operating system must require the change of at least 50 percent of the total number of characters when passwords are changed.
General Purpose Operating System Security Requirements Guide
V-203631
CAT II
Operating systems must enforce 24 hours/1 day as the minimum password lifetime.
General Purpose Operating System Security Requirements Guide
V-203632
CAT II
Operating systems must enforce a 60-day maximum password lifetime restriction.
General Purpose Operating System Security Requirements Guide
V-203634
CAT II
The operating system must enforce a minimum 15-character password length.
General Purpose Operating System Security Requirements Guide
V-203676
CAT II
The operating system must enforce password complexity by requiring that at least one special character be used.
General Purpose Operating System Security Requirements Guide
V-258378
CAT II
Google Android 14 must be configured to enforce a minimum password length of six characters.
Google Android 14 COBO Security Technical Implementation Guide
V-258379
CAT II
Google Android 14 must be configured to not allow passwords that include more than four repeating or sequential characters.
Google Android 14 COBO Security Technical Implementation Guide
V-258409
CAT II
Google Android 14 must be configured to enforce a minimum password length of six characters.
Google Android 14 COPE Security Technical Implementation Guide
V-258410
CAT II
Google Android 14 must be configured to not allow passwords that include more than four repeating or sequential characters.
Google Android 14 COPE Security Technical Implementation Guide
V-267431
CAT II
Google Android 15 must be configured to enforce a minimum password length of six characters.
Google Android 15 COBO Security Technical Implementation Guide
V-267432
CAT II
Google Android 15 must be configured to not allow passwords that include more than four repeating or sequential characters.
Google Android 15 COBO Security Technical Implementation Guide
V-267526
CAT II
Google Android 15 must be configured to enforce a minimum password length of six characters.
Google Android 15 COPE Security Technical Implementation Guide
V-267527
CAT II
Google Android 15 must be configured to not allow passwords that include more than four repeating or sequential characters.
Google Android 15 COPE Security Technical Implementation Guide
V-276749
CAT II
Google Android 16 must be configured to enforce a minimum password length of six characters.
Google Android 16 COBO Security Technical Implementation Guide
V-276750
CAT II
Google Android 16 must be configured to not allow passwords that include more than four repeating or sequential characters.
Google Android 16 COBO Security Technical Implementation Guide
V-276851
CAT II
Google Android 16 must be configured to enforce a minimum password length of six characters.
Google Android 16 COPE Security Technical Implementation Guide
V-276852
CAT II
Google Android 16 must be configured to not allow passwords that include more than four repeating or sequential characters.
Google Android 16 COPE Security Technical Implementation Guide
V-255241
CAT II
SSMC must enforce a minimum 15-character password length.
HPE 3PAR SSMC Operating System Security Technical Implementation Guide
V-255280
CAT II
The HPE 3PAR OS must be configured to enforce a minimum 15-character password length.
HPE 3PAR StoreServ 3.3.x Security Technical Implementation Guide
V-283381
CAT II
The HPE Alletra Storage ArcusOS device must enforce a minimum 15-character password length.
HPE Alletra Storage ArcusOS Network Device Management Security Technical Implementation Guide
V-283382
CAT II
The HPE Alletra Storage ArcusOS device must enforce password complexity by requiring at least one uppercase character, one lowercase character, one numeric character, and one special character be used.
HPE Alletra Storage ArcusOS Network Device Management Security Technical Implementation Guide
V-252190
CAT II
The HPE Nimble must enforce a minimum 15-character password length.
HPE Nimble Storage Array NDM Security Technical Implementation Guide
V-252191
CAT II
The HPE Nimble must enforce password complexity by requiring that at least one uppercase character be used.
HPE Nimble Storage Array NDM Security Technical Implementation Guide