4.017 - DOD information system access does not require the use of a password.

Information

The lack of password protection enables anyone to gain access to the information system, which opens a backdoor opportunity for intruders to compromise the system as well as other resources within the same administrative domain.

Solution

Configure all DoD information systems to require passwords to gain access.

The password required flag can be set by entering the following on a command line- 'Net user <account_name> /passwordreq-yes'.

See Also

http://iasecontent.disa.mil/stigs/zip/Oct2016/U_Windows_Vista_V6R41_STIG.zip

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-2, CAT|I, CCI|CCI-000764, Rule-ID|SV-29548r1_rule, STIG-ID|4.017, Vuln-ID|V-7002

Plugin: Windows

Control ID: 04484018d9b958fd773888fe893a27ee38d1f616f11a267ae5d978bb1e2d8b89