1. Home
  2. Security Hardening
  3. CIS Palo Alto Firewall 8 Benchmark L1 V1.0.0
  4. Ensure ‘Prevent Password Reuse Limit’ is set to 24 or more passwords

Ensure ‘Prevent Password Reuse Limit’ is set to 24 or more passwords

Details

This determines the number of unique passwords that have to be most recently used for a user account before a previous password can be reused.

Rationale:

The longer a user uses the same password, the greater the chance that an attacker can determine the password through brute force attacks. Also, any accounts that may have been compromised will remain exploitable for as long as the password is left unchanged. If password changes are required but password reuse is not prevented, or if users continually reuse a small number of passwords, the effectiveness of a good password policy is greatly reduced. While current guidance emphasizes password length above frequent password changes, not enforcing password re-use guidance adds the temptation of using a small pool of passwords, which can make an attacker’s job easier across an entire infrastructure.

Solution

Navigate to Device > Setup > Management > Minimum Password Complexity.
Set Prevent Password Reuse Limit to greater than or equal to 24
Default Value:
Not enabled.

Supportive Information

The following resource is also helpful.

This security hardening control applies to the following category of controls within NIST 800-53: Identification and Authentication.This control applies to the following type of system Palo_Alto.

References

Source

Updated on July 16, 2022
Was this article helpful?

Related Articles