If multifactor authentication is not supported and passwords must be used, the DataPower Gateway must enforce password complexity by requiring that at least one lower-case character be used.
DISA Rule
SV-79587r1_rule
Vulnerability Number
V-65097
Group Title
SRG-APP-000167-NDM-000255
Rule Version
WSDP-NM-000056
Severity
CAT II
CCI(s)
- CCI-000193 - The information system enforces password complexity by the minimum number of lower case characters used.
Weight
10
Fix Recommendation
Search Bar “Administration” >> Access >> RBM Settings >> Password Policy. Set Require mixed case to On.
Check Contents
Search Bar “Administration” >> Access >> RBM Settings >> Password Policy. If Require mixed case is Off, this is a finding.
Vulnerability Number
V-65097
Documentable
False
Rule Version
WSDP-NM-000056
Severity Override Guidance
Search Bar “Administration” >> Access >> RBM Settings >> Password Policy. If Require mixed case is Off, this is a finding.
Check Content Reference
M
Target Key
2861
Comments