5.4.1.6 Ensure all users last password change date is in the past

Information

All users should have a password change date in the past.

If a user's recorded password change date is in the future, then they could bypass any set password expiration.

Solution

Investigate any users with a password change date in the future and correct them. Locking the account, expiring the password, or resetting the password manually may be appropriate.

See Also

https://workbench.cisecurity.org/benchmarks/24009

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1), CSCv7|4.4

Plugin: Unix

Control ID: 87ee7aa11b44395b3290a857999af24ef7571e6c647a5bec405b0f9a4f2f31a7