1.1 Ensure Minimum Password Length is set to 14 or higher

Information

Defines the minimum length a password can be. The minimum number of characters of a password that is to be allowed for users or SNMP users. Does not apply to passwords that have already been set.

Rationale:

Password length has been found to be a primary factor in characterizing password strength. Passwords that are too short yield to brute force attacks as well as to dictionary attacks using words and commonly chosen passwords.

Solution

Run the following command to set the min-password-length setting.
CLI:

Hostname>set password-controls min-password-length 14

GUI:

Navigate to User Management > Password Policy
Ensure 'Minimum Password Length' is set to 14 or higher.

Default Value:

6

See Also

https://workbench.cisecurity.org/files/2828

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1)(a)

Plugin: CheckPoint

Control ID: 41245fc8a53030b5cbe665559691a97aba250cc818d5a7ccb46ec89f6f6b2189