1. Home
  2. Security Hardening
  3. CIS Check Point Firewall L1 V1.1.0
  4. Ensure Warn users before password expiration is set to 7 days

Ensure Warn users before password expiration is set to 7 days

Details

The number of days before the password expires that the user starts getting warned they will have to change it. A user that does not log in will not see the warning.

Rationale:

Providing an advance warning that a password will be expiring gives users time to think of a secure password. Users caught unaware may choose a simple password or write it down where it may be discovered.

Solution

Run the following command to set the expiration-warning-days setting.
CLI:

Hostname>set password-controls expiration-warning-days 7

GUI:

Navigate to User Management > Password Policy > Mandatory Password Changes
Set ‘Warn users before password expiration’ is set to 7 days or less.

Default Value:

7 days

Supportive Information

The following resource is also helpful.

This security hardening control applies to the following category of controls within NIST 800-53: Access Control.This control applies to the following type of system CheckPoint.

References

Source

Updated on July 16, 2022
Was this article helpful?

Related Articles