SV-222545r508029_rule
V-222545
SRG-APP-000174
APSC-DV-001770
CAT II
10
Configure the application to have a maximum password lifetime of 60 days.
Review the application documentation and interview the application administrator to identify if the application uses passwords for user authentication.
If the application does not use passwords, the requirement is not applicable.
Access the application management interface and view the user password settings page.
Review user password settings and validate the application is configured to expire and force a password change after 60 days.
If user passwords are not configured to expire after 60 days, or if the application does not have the ability to control this setting, this is a finding.
V-222545
False
APSC-DV-001770
Review the application documentation and interview the application administrator to identify if the application uses passwords for user authentication.
If the application does not use passwords, the requirement is not applicable.
Access the application management interface and view the user password settings page.
Review user password settings and validate the application is configured to expire and force a password change after 60 days.
If user passwords are not configured to expire after 60 days, or if the application does not have the ability to control this setting, this is a finding.
M
4093