If multifactor authentication is not supported and passwords must be used, the DataPower Gateway must enforce password complexity by requiring that at least one numeric character be used.
DISA Rule
SV-79589r1_rule
Vulnerability Number
V-65099
Group Title
SRG-APP-000168-NDM-000256
Rule Version
WSDP-NM-000057
Severity
CAT II
CCI(s)
- CCI-000194 - The information system enforces password complexity by the minimum number of numeric characters used.
Weight
10
Fix Recommendation
Search Bar “Administration” >> Access >> RBM Settings >> Password Policy. Set Require number to On.
Check Contents
Search Bar “Administration” >> Access >> RBM Settings >> Password Policy. If Require number is Off, this is a finding.
Vulnerability Number
V-65099
Documentable
False
Rule Version
WSDP-NM-000057
Severity Override Guidance
Search Bar “Administration” >> Access >> RBM Settings >> Password Policy. If Require number is Off, this is a finding.
Check Content Reference
M
Target Key
2861
Comments