CMMC Practice IA.L2-3.5.8 – Password Reuse: Prohibit password reuse for a specified number of generations.
Links to Publicly Available Resources
Consolidation of default passwords for commercial software and hardware products. This document provides assessment guidance for conducting Cybersecurity Maturity Model Certification (CMMC) assessments for Level 2. Nikto is an Open Source (GPL) web server scanner which performs comprehensive tests against web servers for multiple items. The scope of this test is to verify if it is possible to collect a set of valid usernames by interacting with the authentication mechanism of the application. This link discusses the process of testing web applications for default credentials. This SANS guideline provides best practices for creating secure passwords. This is a sample password protection policy from SANS. This SANS whitepaper discusses vendor-supplied passwords that are embedded in software/hardware. US-CERT alert that reviews the risk associated with default passwords on internet-connected systems. In this edition of the On Call Compliance Solutions Compliance Tip of the Week, we focus on how Password lifetime restrictions do not apply to temporary passwords. Let’s talk about NIST 800-171 Control 3.5.8 Prohibit password reuse for a specified number of generations.
Discussion [NIST SP 800-171 R2]
Password lifetime restrictions do not apply to temporary passwords.
Further Discussion
Individuals may not reuse their passwords for a defined period of time and a set number of passwords generated.