5.2.7 Password Age

Information

Passwords should be changed periodically to reduce exposure

Solution

Perform the following to ensure the system is configured as prescribed:

1. Run the following command in Terminal:
pwpolicy -getaccountpolicies | egrep policyAttributeExpiresEveryNDays

2. Verify the value returned
<string>policyAttributeCurrentTime &gt; policyAttributeLastPasswordChangeTime + policyAttributeExpiresEveryNDays * 24 * 60 * 60</string>
<key>policyAttributeExpiresEveryNDays</key>

Should contain 90 or less

See Also

https://workbench.cisecurity.org/files/301

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1)(d)

Plugin: Unix

Control ID: 4d3d7643c99a0b4bb9768b9a2a4614c5b45e17640fe3ba206b9813d23a51d73e