V-222543
Application Security and Development Security Technical Implementation Guide
Title
The application must transmit only cryptographically-protected passwords.
Description
<VulnDiscussion>Use of passwords for application authentication is intended only for limited situations and should not be used as a replacement for two-factor CAC-enabled authentication. Examples of situations where a user ID and password might be used include but are not limited to: - When the application user base does not have a CAC and is not a current DoD employee, member of the military, or a DoD contractor. - When an application user has been officially designated as a Temporary Except...
Fix Text (Documentation Requirement)
Configure the application to encrypt passwords when they are being transmitted.