STIGQter STIGQter: STIG Summary: HP FlexFabric Switch NDM Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 24 Jul 2020:

The HP FlexFabric Switch must enforce 24 hours/1 day as the minimum password lifetime.

DISA Rule

SV-80705r1_rule

Vulnerability Number

V-66215

Group Title

SRG-APP-000173-NDM-000260

Rule Version

HFFS-ND-000062

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the HP FlexFabric Switch to enforce 24 hours/1 day as the minimum password lifetime.

[HP] password-control enable
[HP] password-control update-interval 24

Check Contents

Determine if the HP FlexFabric Switch enforces 24 hours/1 day as the minimum password lifetime.

[HP] display password-control

Global password control configurations:
Password control: Enabled
Password aging: Enabled (90 days)
Password length: Enabled (15 characters)
Password composition: Enabled (1 types, 1 characters per type)
Password history: Enabled (max history records: 4)
Early notice on password expiration: 7 days
Maximum login attempts: 3
Action for exceeding login attempts: Lock user for 1 minutes
Minimum interval between two updates: 24 hours

If the HP FlexFabric Switch or its associated authentication server does not enforce 24 hours/1 day as the minimum password lifetime, this is a finding.

Vulnerability Number

V-66215

Documentable

False

Rule Version

HFFS-ND-000062

Severity Override Guidance

Determine if the HP FlexFabric Switch enforces 24 hours/1 day as the minimum password lifetime.

[HP] display password-control

Global password control configurations:
Password control: Enabled
Password aging: Enabled (90 days)
Password length: Enabled (15 characters)
Password composition: Enabled (1 types, 1 characters per type)
Password history: Enabled (max history records: 4)
Early notice on password expiration: 7 days
Maximum login attempts: 3
Action for exceeding login attempts: Lock user for 1 minutes
Minimum interval between two updates: 24 hours

If the HP FlexFabric Switch or its associated authentication server does not enforce 24 hours/1 day as the minimum password lifetime, this is a finding.

Check Content Reference

M

Target Key

2971

Comments