1.1.6 Store passwords using reversible encryption

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

The Windows authentication model allows storage of a password hash rather than the actual password.

Solution

Make sure 'Store passwords using reversible encryption' is Disabled.

See Also

https://workbench.cisecurity.org/files/10

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1), CCE|CCE-2289-7, CSCv6|16.13, CSCv6|16.14

Plugin: Windows

Control ID: 8fdd1892a5159f6cee8003d07ce8447b176b07c506f925c8547e29add4541f53