NIST 800-171 v2

110 security requirements available

3.5.7Derived Requirement

Identification and Authentication

Security Requirement

Enforce a minimum password complexity and change of characters when new passwords are created.

Discussion

This requirement applies to single-factor authentication of individuals using passwords as individual or group authenticators, and in a similar manner, when passwords are used as part of multifactor authenticators. The number of changed characters refers to the number of changes required with respect to the total number of positions in the current password. To mitigate certain brute force attacks against passwords, organizations may also consider salting passwords.

Framework
NIST SP 800-171 Rev 2
Family
Identification and Authentication
Requirement Type
derived

Related Frameworks

32 paths across 2 frameworks
NIST 800-531 mapping
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
CCI31 mappings
CCI-000192
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000193
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000194
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000195
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000196
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000197
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000198
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000199
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000200
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000205
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001611
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001612
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001613
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001614
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001615
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001616
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001617
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001618
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001619
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002041
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-004057
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-004058
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-004059
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-004060
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-004061
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-004062
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-004063
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-004064
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-004065
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-004066
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-004067
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent

Related STIGs

302 STIGs reach this control through 101 CCIs via 800-53 control IA-5. Expand a row to see the responsible NICE and O*NET roles.

Operating System — Desktop

7 STIGs

Operating System — Server

47 STIGs
Oracle Linux 9 Security Technical Implementation Guide
V1R52026-02-1728 of 448 findings match
IBM AIX 7.x Security Technical Implementation Guide
V3R22026-02-0623 of 283 findings match
Show 39 more STIGs in this category →
IBM AIX 7.x Security Technical Implementation Guide
32024-08-1623 of 283 findings match
Oracle Linux 8 Security Technical Implementation Guide
V2R82026-02-1320 of 375 findings match
Amazon Linux 2023 Security Technical Implementation Guide
V1R32026-02-2717 of 187 findings match
Anduril NixOS Security Technical Implementation Guide
V1R22025-08-1914 of 103 findings match
Solaris 11 SPARC Security Technical Implementation Guide
V3R52026-02-1910 of 217 findings match
Solaris 11 X86 Security Technical Implementation Guide
V3R52026-02-1910 of 216 findings match

Operating System — Mainframe

11 STIGs
Mainframe Product Security Requirements Guide
V3R42025-09-1022 of 194 findings match
Mainframe Product Security Requirements Guide
32024-12-0522 of 193 findings match
IBM z/OS ACF2 Security Technical Implementation Guide
V9R82026-03-0915 of 225 findings match
IBM z/OS TSS Security Technical Implementation Guide
V9R82026-03-0912 of 230 findings match
IBM z/OS TSS Security Technical Implementation Guide
92025-06-2412 of 231 findings match
IBM z/OS RACF Security Technical Implementation Guide
V9R82026-03-0911 of 222 findings match
Show 3 more STIGs in this category →
CA IDMS Security Technical Implementation Guide
V2R12024-09-132 of 74 findings match

Operating System — Mobile

36 STIGs
Show 28 more STIGs in this category →

Network Device

76 STIGs
AAA Services Security Requirements Guide
V2R22024-12-0421 of 77 findings match
Domain Name System (DNS) Security Requirements Guide
42024-07-0217 of 118 findings match
Domain Name System (DNS) Security Requirements Guide
V4R22025-12-1916 of 119 findings match
Network Device Management Security Requirements Guide
V5R32025-02-1114 of 104 findings match
Network Device Management Security Requirements Guide
V5R42025-09-1014 of 105 findings match
Riverbed NetIM OS Security Technical Implementation Guide
V1R12025-10-0210 of 154 findings match
Show 68 more STIGs in this category →
Cisco ISE NDM Security Technical Implementation Guide
V2R32025-12-117 of 53 findings match
BIND 9.x Security Technical Implementation Guide
V3R22026-02-256 of 73 findings match
Cisco ASA NDM Security Technical Implementation Guide
V2R42025-12-086 of 47 findings match
Application Layer Gateway Security Requirements Guide
V2R32025-09-155 of 160 findings match
BIND 9.x Security Technical Implementation Guide
22024-02-155 of 70 findings match
Cisco ASA VPN Security Technical Implementation Guide
V2R22024-08-225 of 41 findings match
F5 NGINX Security Technical Implementation Guide
V1R12026-01-075 of 32 findings match
Cisco ACI NDM Security Technical Implementation Guide
V1R22025-12-112 of 26 findings match
RUCKUS ICX NDM Security Technical Implementation Guide
V1R12025-05-281 of 25 findings match

Database

25 STIGs
Database Security Requirements Guide
V4R52026-02-2615 of 142 findings match
Database Security Requirements Guide
42024-12-0415 of 142 findings match
Show 17 more STIGs in this category →

Web / Application Server

29 STIGs
Web Server Security Requirements Guide
V4R42025-09-1013 of 126 findings match
Web Server Security Requirements Guide
42025-02-1213 of 124 findings match
Application Server Security Requirements Guide
V4R42025-09-108 of 137 findings match
Application Server Security Requirements Guide
42025-02-118 of 128 findings match
Show 21 more STIGs in this category →

Virtualization / Container

30 STIGs
Container Platform Security Requirements Guide
V2R42025-09-1021 of 188 findings match
Container Platform Security Requirements Guide
22025-05-1521 of 187 findings match
Virtual Machine Manager Security Requirements Guide
22024-12-0619 of 193 findings match
Virtual Machine Manager Security Requirements Guide
V2R32025-09-1019 of 198 findings match
Show 22 more STIGs in this category →
Kubernetes Security Technical Implementation Guide
V2R62026-02-122 of 92 findings match

Cloud / Identity Service

4 STIGs

Endpoint Security Management

22 STIGs
Central Log Server Security Requirements Guide
V3R42026-02-1221 of 127 findings match
Central Log Server Security Requirements Guide
32024-12-0421 of 125 findings match
HYCU Protege Security Technical Implementation Guide
V1R22026-03-048 of 55 findings match
Show 14 more STIGs in this category →
ISEC7 Sphere Security Technical Implementation Guide
V3R12024-08-203 of 34 findings match
Tanium 7.x Security Technical Implementation Guide
V2R32025-05-142 of 98 findings match

Productivity Application

12 STIGs

Uncategorized

3 STIGs