STIGUI
V-285623CAT II — Medium severitySV-285623r1273116_rule

The Content Analysis System (CAS) must enforce a minimum 15-character password length.

Rule version BCAS-ND-001370 · STIG v1 · 2026-09-16

Discussion

Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at guessing and brute-force attacks. Password length is one factor of several that helps to determine strength and how long it takes to crack a password.

The shorter the password, the lower the number of possible combinations that must be tested before the password is compromised. Use of more characters in a password helps to increase exponentially the time and/or resources required to compromise the password.

Check

Verify "min-length" is set to "15" and "min-groups" is set to "4" with the following steps:

1. Log on to the SSH CLI with an administrative account. 2. Enter "show running-config authentication password-policy". 3. Review the output for the specific length and group requirements.

If "min-length" is not set to "15" or "min-groups" is not set to "4", this is a finding.

Fix

Configure password "min-length" to "15" and "min-groups" to "4" with the following steps:

1. Log on to the SSH CLI with an administrative account. 2. Enter "enable" and provide the password. 3. Enter "configure terminal". 4. Set the minimum password length by entering "authentication password-policy min-length 15". 5. Set the minimum character groups required by entering "authentication password-policy min-groups 4". 6. Enter "exit" to return to the config context, and then enter "exit" again to leave configuration mode.

Identifiers

Group ID
V-285623
Group title
SRG-APP-000164-NDM-000252
Rule ID
SV-285623r1273116_rule
Check ID
C-90303r1272986_chk
Fix ID
F-90208r1272987_fix