If multifactor authentication is not supported and passwords must be used, the DataPower Gateway must enforce password complexity by requiring that at least one upper-case character be used.
DISA Rule
SV-79585r1_rule
Vulnerability Number
V-65095
Group Title
SRG-APP-000166-NDM-000254
Rule Version
WSDP-NM-000055
Severity
CAT II
CCI(s)
- CCI-000192 - The information system enforces password complexity by the minimum number of upper case characters used.
Weight
10
Fix Recommendation
Search Bar “Administration” >> Access >> RBM Settings >> Password Policy. Set Require mixed case to On.
Check Contents
Search Bar “Administration” >> Access >> RBM Settings >> Password Policy. If Require mixed case is Off, this is a finding.
Vulnerability Number
V-65095
Documentable
False
Rule Version
WSDP-NM-000055
Severity Override Guidance
Search Bar “Administration” >> Access >> RBM Settings >> Password Policy. If Require mixed case is Off, this is a finding.
Check Content Reference
M
Target Key
2861
Comments