Password Policies

From attackics
Jump to navigation Jump to search
Password Policies
Mitigation
ID M1027
NIST SP 800-53 Rev. 4 IA-5
IEC 62443-3-3:2013 SR 1.5
IEC 62443-4-2:2019 CR 1.5

Description

Set and enforce secure password policies for accounts.


Techniques Addressed by Mitigation

NameUse
Default CredentialsReview vendor documents and security alerts for potentially unknown or overlooked default credentials within existing devices
External Remote ServicesSet and enforce secure password policies for accounts.
Valid AccountsApplications and appliances that utilize default username and password should be changed immediately after the installation, and before deployment to a production environment. 1