CSCv7|4.2

Title

Change Default Passwords

Description

Before deploying any new asset, change all default passwords to have values consistent with administrative level accounts.

Reference Item Details

Category: Controlled Use of Administrative Privileges

Audit Items

View all Reference Audit Items

NamePluginAudit Name
1.1.1 Ensure 'Logon Password' is setCiscoCIS Cisco Firewall v8.x L1 v4.2.0
1.1.1 Ensure 'Logon Password' is setCiscoCIS Cisco ASA 9.x Firewall L1 v1.0.0
1.1.1 Ensure 'Logon Password' is setCiscoCIS Cisco Firewall ASA 9 L1 v4.1.0
1.1.1 Ensure default password of root is not allowedF5CIS F5 Networks v1.0.0 L1
1.1.2 Ensure default password of admin is not usedF5CIS F5 Networks v1.0.0 L1
1.1.3 Configure Secure Password Policy - Ensure Maximum Login FailuresF5CIS F5 Networks v1.0.0 L1
1.1.3 Configure Secure Password Policy - EnsurePassword MemoryF5CIS F5 Networks v1.0.0 L1
1.1.3 Configure Secure Password Policy - Expiration WarningF5CIS F5 Networks v1.0.0 L1
1.1.3 Configure Secure Password Policy - Maximum DurationF5CIS F5 Networks v1.0.0 L1
1.1.3 Configure Secure Password Policy - Minimum DurationF5CIS F5 Networks v1.0.0 L1
1.1.3 Configure Secure Password Policy - Minimum Password LengthF5CIS F5 Networks v1.0.0 L1
1.1.3 Configure Secure Password Policy - Required LowercaseF5CIS F5 Networks v1.0.0 L1
1.1.3 Configure Secure Password Policy - Required NumericF5CIS F5 Networks v1.0.0 L1
1.1.3 Configure Secure Password Policy - Required Special CharactersF5CIS F5 Networks v1.0.0 L1
1.1.3 Configure Secure Password Policy - Required UppercaseF5CIS F5 Networks v1.0.0 L1
1.1.3 Configure Secure Password Policy - Secure Password EnforcementF5CIS F5 Networks v1.0.0 L1
1.1.3 Configure Secure Password Policy - User LockoutF5CIS F5 Networks v1.0.0 L1
1.3.1 Ensure 'Minimum Password Complexity' is enabledPalo_AltoCIS Palo Alto Firewall 8 Benchmark L1 v1.0.0
1.3.2 Ensure 'Minimum Length' is greater than or equal to 12Palo_AltoCIS Palo Alto Firewall 9 v1.1.0 L1
1.3.2 Ensure 'Minimum Length' is greater than or equal to 12Palo_AltoCIS Palo Alto Firewall 11 v1.0.0 L1
1.3.2 Ensure 'Minimum Length' is greater than or equal to 12Palo_AltoCIS Palo Alto Firewall 8 Benchmark L1 v1.0.0
1.3.2 Ensure 'Minimum Length' is greater than or equal to 12Palo_AltoCIS Palo Alto Firewall 10 v1.1.0 L1
1.3.3 Ensure 'Minimum Uppercase Letters' is greater than or equal to 1Palo_AltoCIS Palo Alto Firewall 9 v1.1.0 L1
1.3.3 Ensure 'Minimum Uppercase Letters' is greater than or equal to 1Palo_AltoCIS Palo Alto Firewall 11 v1.0.0 L1
1.3.3 Ensure 'Minimum Uppercase Letters' is greater than or equal to 1Palo_AltoCIS Palo Alto Firewall 10 v1.1.0 L1
1.3.4 Ensure 'Minimum Lowercase Letters' is greater than or equal to 1Palo_AltoCIS Palo Alto Firewall 9 v1.1.0 L1
1.3.4 Ensure 'Minimum Lowercase Letters' is greater than or equal to 1Palo_AltoCIS Palo Alto Firewall 10 v1.1.0 L1
1.3.4 Ensure 'Minimum Lowercase Letters' is greater than or equal to 1Palo_AltoCIS Palo Alto Firewall 11 v1.0.0 L1
1.3.5 Ensure 'Minimum Numeric Letters' is greater than or equal to 1Palo_AltoCIS Palo Alto Firewall 11 v1.0.0 L1
1.3.5 Ensure 'Minimum Numeric Letters' is greater than or equal to 1Palo_AltoCIS Palo Alto Firewall 9 v1.1.0 L1
1.3.5 Ensure 'Minimum Numeric Letters' is greater than or equal to 1Palo_AltoCIS Palo Alto Firewall 10 v1.1.0 L1
1.3.7 Ensure 'Required Password Change Period' is less than or equal to 90 daysPalo_AltoCIS Palo Alto Firewall 9 v1.1.0 L1
1.3.7 Ensure 'Required Password Change Period' is less than or equal to 90 daysPalo_AltoCIS Palo Alto Firewall 10 v1.1.0 L1
1.3.7 Ensure 'Required Password Change Period' is less than or equal to 90 daysPalo_AltoCIS Palo Alto Firewall 11 v1.0.0 L1
1.3.8 Ensure 'New Password Differs By Characters' is greater than or equal to 3Palo_AltoCIS Palo Alto Firewall 9 v1.1.0 L1
1.3.8 Ensure 'New Password Differs By Characters' is greater than or equal to 3Palo_AltoCIS Palo Alto Firewall 10 v1.1.0 L1
1.3.8 Ensure 'New Password Differs By Characters' is greater than or equal to 3Palo_AltoCIS Palo Alto Firewall 11 v1.0.0 L1
1.3.8 Ensure 'New Password Differs By Characters' is greater than or equal to 3Palo_AltoCIS Palo Alto Firewall 8 Benchmark L1 v1.0.0
1.3.9 Ensure 'Prevent Password Reuse Limit' is set to 24 or more passwordsPalo_AltoCIS Palo Alto Firewall 9 v1.1.0 L1
1.3.9 Ensure 'Prevent Password Reuse Limit' is set to 24 or more passwordsPalo_AltoCIS Palo Alto Firewall 11 v1.0.0 L1
1.3.9 Ensure 'Prevent Password Reuse Limit' is set to 24 or more passwordsPalo_AltoCIS Palo Alto Firewall 10 v1.1.0 L1
1.3.10 Ensure 'Password Profiles' do not existPalo_AltoCIS Palo Alto Firewall 9 v1.1.0 L1
1.3.10 Ensure 'Password Profiles' do not existPalo_AltoCIS Palo Alto Firewall 11 v1.0.0 L1
1.3.10 Ensure 'Password Profiles' do not existPalo_AltoCIS Palo Alto Firewall 10 v1.1.0 L1
1.4.1.3 Ensure known default accounts do not existCiscoCIS Cisco Firewall v8.x L1 v4.2.0
1.4.1.3 Ensure known default accounts do not existCiscoCIS Cisco Firewall ASA 9 L1 v4.1.0
1.4.1.3 Ensure known default accounts do not existCiscoCIS Cisco ASA 9.x Firewall L1 v1.0.0
2.10.2 Ensure Require Password After Screen Saver Begins or Display Is Turned Off Is Enabled for 5 Seconds or ImmediatelyUnixCIS Apple macOS 13.0 Ventura v2.0.0 L1
2.10.2 Ensure Require Password After Screen Saver Begins or Display Is Turned Off Is Enabled for 5 Seconds or ImmediatelyUnixCIS Apple macOS 14.0 Sonoma v1.0.0 L1
2.12.3 Ensure Automatic Login Is DisabledUnixCIS Apple macOS 13.0 Ventura v2.0.0 L1