1. Home
  2. Security Hardening
  3. DISA Windows Server 2016 STIG V2R3
  4. WN16-00-000060 – Manually managed application account passwords must be at least 15 characters in length.

WN16-00-000060 – Manually managed application account passwords must be at least 15 characters in length.

Details

Application/service account passwords must be of sufficient length to prevent being easily cracked. Application/service accounts that are manually managed must have passwords at least 15 characters in length.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Establish a policy that requires application/service account passwords that are manually managed to be at least 15 characters in length. Ensure the policy is enforced.

Supportive Information

The following resource is also helpful.

This security hardening control applies to the following category of controls within NIST 800-53: Identification and Authentication.This control applies to the following type of system Windows.

References

Source

Updated on July 16, 2022
Was this article helpful?

Related Articles