Rule ID
SV-50516r1_rule
Version
V1R2
CCIs
CCI-000200
Password complexity, or strength, is a measure of the effectiveness of a password in resisting guessing and brute force attacks. Remembering the prior five device unlock passwords enables the operating system from permitting those passwords to be reused, which increases the resistance against password attacks.
If the local command determines that there is not a need for password rotation based on the expected operational use of the device, this requirement does not apply. On BlackBerry Device Service: "Maximum Password History" IT Policy rule must be set to 5 or more. Otherwise, this is a finding.
On BlackBerry Device Service: Set "Maximum Password History" IT Policy rule to: 5.