3.5 Ensure 'PASSWORD_REUSE_TIME' Is Greater than or Equal to '365'

Information

As reusing the same password after only a short period of time has passed makes the success of brute-force login attacks more likely, this value should be set according to the needs of the organization.

Solution

Remediate this setting by executing the following SQL statement. ALTER PROFILE DEFAULT LIMIT PASSWORD_REUSE_TIME 365;

See Also

https://workbench.cisecurity.org/files/601

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1)(e)

Plugin: OracleDB

Control ID: cb09a694467bfc233de3fe070cbce8063e0d6e24b49dbf99dd03b1542d9da85e