20.35 Ensure 'Manually managed application account passwords be changed at least annually or when a system administrator with knowledge of the password leaves the organization' (STIG only)

Information

This policy setting ensures that all manually managed application account passwords are changed at least annually or when a system administrator with knowledge of the password leaves the organization.

Setting application account passwords to expire may cause applications to stop functioning. However, not changing them on a regular basis exposes them to attack. If managed service accounts are used, this alleviates the need to manually change application account passwords.

Solution

Change passwords for manually managed application/service accounts at least annually or when an administrator with knowledge of the password leaves the organization.

Impact:

Manually managed application account passwords will need to be changed at least annually.

See Also

https://workbench.cisecurity.org/benchmarks/20002

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b.

Plugin: Windows

Control ID: 13d7befda6644564d30c8c9907c1196d43d4e84b5fb14fa6f4ba024fdc23545b