20.34 Ensure 'Manually managed application account passwords are at least 15 characters in length'

Information

This policy setting ensures that all manually managed application account passwords are at least 15 characters in length.

The recommended STIG state for this setting is: 15 characters or more

Rationale:

Application account passwords must be of sufficient length to prevent being easily cracked. Application accounts that are manually managed must have passwords at least 15 characters in length.

Impact:

All manually managed account will need to be at least 15 characters in length.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Establish a policy that requires application/service account passwords that are manually managed to be 15 characters or more in length. Ensure that the policy is enforced.

Default Value:

N/A




Additional Information:

Microsoft Windows Server 2016 Security Technical Implementation Guide:

Version 2, Release 2, Benchmark Date: May 04, 2021



Vul ID: V-224823

Rule ID: SV-224823r569186_rule

STIG ID: WN16-00-000060

Severity: CAT II

See Also

https://workbench.cisecurity.org/files/3476

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1), CSCv7|4.4

Plugin: Windows

Control ID: 68e76d90beb4e463931a8624c16ced73981f010e09430c07e6b6cb13e02b0492