Network Device Management Rules : Ensuring passwords enforce 60-day maximum lifetime
  
Ensuring passwords enforce 60-day maximum lifetime
Rule Title: RiOS must enforce a 60-day maximum password lifetime restriction.
STIG ID: RICX-DM-000123
Rule ID: SV-77463r1_rule Severity: CAT II
Vuln ID: V-62973 Class: Unclass
Any password, no matter how complex, can eventually be cracked. Therefore, passwords need to be changed at specific intervals.
One method of minimizing this risk is to use complex passwords and periodically change them. If the network device does not limit the lifetime of passwords and force users to change their passwords, there is the risk that the passwords could be compromised.
This requirement does not include emergency administration accounts, which are meant for access to the network device in case of failure. These accounts are not required to have maximum password lifetime restrictions.
Verifying passwords enforce 60-day maximum lifetime
Verify that RiOS is configured to enforce a 60-day maximum password lifetime restriction.
1. Connect to the Management Console.
2. Choose Administration > Security: Password Policy to display the Password Policy page.
3. Verify that the Days Before Password Expires is set to 60, If the Days Before Password Expires is not set to 60, this is a security vulnerability finding.
Configuring passwords to enforce 60-day maximum lifetime
Configure RiOS to enforce a 60-day maximum password lifetime.
1. Connect to the Management Console.
2. Choose Administration > Security: Password Policy to display the Password Policy page.
3. Specify the value of the Days Before Password Expires text box to 60.
4. Click Apply.