3.4 Ensure 'PASSWORD_REUSE_MAX' Is Greater than or Equal to '20'

Information

As allowing reuse of a password within a short period of time after the password's initial use can make the success of both social-engineering and brute-force password-based attacks more likely, this value should be set according to the needs of the organization.

Solution

Remediate this setting by executing the following SQL statement. ALTER PROFILE DEFAULT LIMIT PASSWORD_REUSE_MAX 20;

See Also

https://workbench.cisecurity.org/files/601

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1)(e)

Plugin: OracleDB

Control ID: ebe58097bb08b1d0480d2cdf42d967760c4d23225c624b56d94e48f20a667014