Skip to main content
CUI

Documentation - V-222543

V-222543

Application Security and Development Security Technical Implementation Guide

CAT I

Title

The application must transmit only cryptographically-protected passwords.

Description

<VulnDiscussion>Use of passwords for application authentication is intended only for limited situations and should not be used as a replacement for two-factor CAC-enabled authentication. Examples of situations where a user ID and password might be used include but are not limited to: - When the application user base does not have a CAC and is not a current DoD employee, member of the military, or a DoD contractor. - When an application user has been officially designated as a Temporary Except...

Fix Text (Documentation Requirement)

Configure the application to encrypt passwords when they are being transmitted.

Documentation Status

Cancel
CUI