1. Home
  2. Security Hardening
  3. DISA Windows Server 2012 And 2012 R2 MS STIG V3R3
  4. WN12-AC-000009 – Reversible password encryption must be disabled.

WN12-AC-000009 – Reversible password encryption must be disabled.

Details

Storing passwords using reversible encryption is essentially the same as storing clear-text versions of the passwords. For this reason, this policy must never be enabled.

Solution

Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Account Policies -> Password Policy -> ‘Store password using reversible encryption’ to ‘Disabled’.

Supportive Information

The following resource is also helpful.

This security hardening control applies to the following category of controls within NIST 800-53: Identification and Authentication.This control applies to the following type of system Windows.

References

Source

Updated on July 16, 2022
Was this article helpful?

Related Articles