3.7 Ensure 'PASSWORD_VERIFY_FUNCTION' Is Set for All Profiles

Information

The PASSWORD_VERIFY_FUNCTION determines password settings requirements when a user password is changed at the SQL command prompt. It should be set for all profiles. Note that this setting does not apply for users managed by the Oracle password file.

Rationale:

Requiring users to apply the 12c security features in password creation, such as forcing mixed-case complexity, blocking of simple combinations, and enforcing change/history settings can potentially thwart logins by an unauthorized user.

Solution

Create a custom password verification function which fulfills the password requirements of the organization.

See Also

https://workbench.cisecurity.org/files/2741

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1), CSCv6|16, CSCv7|4.4

Plugin: OracleDB

Control ID: 6c5d07588b1c7ce13e7a2818af1c835e4982b83699c428d7f673c2e733305f36