Rule version BCAS-ND-001370 · STIG v1 · 2026-09-16
Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at guessing and brute-force attacks. Password length is one factor of several that helps to determine strength and how long it takes to crack a password.
The shorter the password, the lower the number of possible combinations that must be tested before the password is compromised. Use of more characters in a password helps to increase exponentially the time and/or resources required to compromise the password.
Verify "min-length" is set to "15" and "min-groups" is set to "4" with the following steps:
1. Log on to the SSH CLI with an administrative account. 2. Enter "show running-config authentication password-policy". 3. Review the output for the specific length and group requirements.
If "min-length" is not set to "15" or "min-groups" is not set to "4", this is a finding.
Configure password "min-length" to "15" and "min-groups" to "4" with the following steps:
1. Log on to the SSH CLI with an administrative account. 2. Enter "enable" and provide the password. 3. Enter "configure terminal". 4. Set the minimum password length by entering "authentication password-policy min-length 15". 5. Set the minimum character groups required by entering "authentication password-policy min-groups 4". 6. Enter "exit" to return to the config context, and then enter "exit" again to leave configuration mode.