22.06.2016 Views

CIS Microsoft Windows 10 Enterprise RTM (Release 1507) Benchmark

CIS_Microsoft_Windows_10_Enterprise_RTM_Release_1507_Benchmark_v1.0.0

CIS_Microsoft_Windows_10_Enterprise_RTM_Release_1507_Benchmark_v1.0.0

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

1.1.2 (L1) Set 'Maximum password age' to '60 or fewer days, but not 0'<br />

(Scored)<br />

Profile Applicability:<br />

Level 1<br />

Level 1 + BitLocker<br />

Description:<br />

This policy setting defines how long a user can use their password before it expires.<br />

Values for this policy setting range from 0 to 999 days. If you set the value to 0, the<br />

password will never expire.<br />

Because attackers can crack passwords, the more frequently you change the password the<br />

less opportunity an attacker has to use a cracked password. However, the lower this value<br />

is set, the higher the potential for an increase in calls to help desk support due to users<br />

having to change their password or forgetting which password is current.<br />

The recommended state for this setting is 60 or fewer days, but not 0.<br />

Rationale:<br />

The longer a password exists the higher the likelihood that it will be compromised by a<br />

brute force attack, by an attacker gaining general knowledge about the user, or by the user<br />

sharing the password. Configuring the Maximum password age setting to 0 so that users<br />

are never required to change their passwords is a major security risk because that allows a<br />

compromised password to be used by the malicious user for as long as the valid user is<br />

authorized access.<br />

Audit:<br />

Navigate to the UI Path articulated in the Remediation section and confirm it is set as<br />

prescribed.<br />

Remediation:<br />

To establish the recommended configuration via GP, set the following UI path to 60 or<br />

fewer days, but not 0:<br />

Computer Configuration\Policies\<strong>Windows</strong> Settings\Security Settings\Account<br />

Policies\Password Policy\Maximum password age<br />

36 | P a g e

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!