If multifactor authentication is not supported and passwords must be used, the DataPower Gateway must enforce password complexity by requiring that at least one special character be used.
DISA Rule
SV-79591r1_rule
Vulnerability Number
V-65101
Group Title
SRG-APP-000169-NDM-000257
Rule Version
WSDP-NM-000058
Severity
CAT II
CCI(s)
- CCI-001619 - The information system enforces password complexity by the minimum number of special characters used.
Weight
10
Fix Recommendation
Search Bar “Administration” >> Access >> RBM Settings >> Password Policy. Set Require non- alphanumeric to On.
Check Contents
Search Bar “Administration” >> Access >> RBM Settings >> Password Policy. If Require non-alphanumeric is Off, this is a finding.
Vulnerability Number
V-65101
Documentable
False
Rule Version
WSDP-NM-000058
Severity Override Guidance
Search Bar “Administration” >> Access >> RBM Settings >> Password Policy. If Require non-alphanumeric is Off, this is a finding.
Check Content Reference
M
Target Key
2861
Comments