STIGUI
V-285628CAT II — Medium severitySV-285628r1273168_rule

The Content Analysis System (CAS) must require that when a password is changed, the characters are changed in at least eight of the positions within the password.

Rule version BCAS-ND-001420 · STIG v1 · 2026-09-16

Discussion

If the application allows the user to consecutively reuse extensive portions of passwords, this increases the chances of password compromise by increasing the window of opportunity for attempts at guessing and brute-force attacks.

The number of changed characters refers to the number of changes required with respect to the total number of positions in the current password. In other words, characters may be the same within the two passwords; however, the positions of the like characters must be different.

Multifactor authentication (MFA) is required for all administrative and user accounts on network devices, except for an account of last resort and (where applicable) a root account. Passwords should only be used when MFA using PKI is not available, and for the account of last resort and root account.

Check

Verify "min-changes" is set to "8" with the following steps:

1. Log on to the SSH CLI with an administrative account. 2. Enter "show running-config authentication password-policy". 3. Review the output for the minimum character changes requirement.

If "min-changes" is not set to "8", this is a finding.

Fix

Configure password "min-changes" to "8" with the following steps:

1. Log on to the SSH CLI with an administrative account. 2. Enter "enable" and provide the password. 3. Enter "configure terminal". 4. Set the minimum character change requirement by entering "authentication password-policy min-changes 8". 5. Enter "exit" to return to the config context, and then enter "exit" again to leave configuration mode.

Identifiers

Group ID
V-285628
Group title
SRG-APP-000170-NDM-000329
Rule ID
SV-285628r1273168_rule
Check ID
C-90308r1273001_chk
Fix ID
F-90213r1273002_fix