The operating system must prevent the use of dictionary words for passwords.

Overview

Finding IDVersionRule IDIA ControlsSeverity
V-203778SRG-OS-000480-GPOS-00225SV-203778r991587_ruleCCI-000366medium
Description
If the operating system allows the user to select passwords based on dictionary words, then this increases the chances of password compromise by increasing the opportunity for successful guesses and brute-force attacks.
STIGDate
General Purpose Operating System Security Requirements Guide2024-12-04

Related Frameworks

4 paths across 3 frameworks
NIST 800-531 mapping
CM-6
1.00
  • DISA · 3 · disa_xccdf · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
NIST 800-1712 mappings
3.4.1
1.00
  • DISA · 3 · disa_xccdf · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
3.4.2
1.00
  • DISA · 3 · disa_xccdf · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
CCI1 mapping
CCI-000366
1.00
  • DISA · 3 · disa_xccdf · related

Details

Check Text (C-203778r991587_chk)

Verify the operating system prevents the use of dictionary words for passwords. If it does not, this is a finding.

Fix Text (F-3903r375726_fix)

Configure the operating system to prevent the use of dictionary words for passwords.