Skip to main content
CUI

Documentation - V-222546

V-222546

Application Security and Development Security Technical Implementation Guide

CAT II

Title

The application must prohibit password reuse for a minimum of five generations.

Description

<VulnDiscussion>Use of passwords for application authentication is intended only for limited situations and should not be used as a replacement for two-factor CAC-enabled authentication. Examples of situations where a user ID and password might be used include but are not limited to: - When the application user base does not have a CAC and is not a current DOD employee, member of the military, or a DOD contractor. - When an application user has been officially designated as a Temporary Excepti...

Fix Text (Documentation Requirement)

Configure the application to prohibit password reuse for up to five passwords.

Documentation Status

Cancel
CUI