1. Home
  2. Security Hardening
  3. DISA Windows Server 2012 And 2012 R2 DC STIG V3R3
  4. WN12-AC-000008 – The built-in Windows password complexity policy must be enabled.

WN12-AC-000008 – The built-in Windows password complexity policy must be enabled.

Details

The use of complex passwords increases their strength against attack. The built-in Windows password complexity policy requires passwords to contain at least 3 of the 4 types of characters (numbers, upper- and lower-case letters, and special characters), as well as preventing the inclusion of user names or parts of.

Solution

Configure the policy value for Computer Configuration >> Windows Settings -> Security Settings >> Account Policies >> Password Policy >> ‘Password must meet complexity requirements’ to ‘Enabled’.

Supportive Information

The following resource is also helpful.

This security hardening control applies to the following category of controls within NIST 800-53: Identification and Authentication.This control applies to the following type of system Windows.

References

Source

Updated on July 16, 2022
Was this article helpful?

Related Articles