IA
Identification And Authentication
2
3.5.8
Prohibit password reuse for a specified number of generations.
Individuals may not reuse passwords for a defined period of time and a set number of passwords generated. Example You are in charge of setting your organization’s password rules. You define how often individuals can reuse their passwords and the minimum number of password generations before reuse. Using new passwords helps provide increased network security.
Prohibit password reuse for a specified number of generations.
Password lifetime restrictions do not apply to temporary passwords.
N/A
CIS Controls v7.1 4.2, 4.4
NIST SP 800-53 Rev 4 IA-5(1)
NIST SP 800-171 Rev 1 3.5.8
NIST CSF v1.1 PR.AC-1, PR.AC-6, PR.AC-7
IA.2.079.[a] the number of generations during which a password cannot be reused is specified and
IA.2.079.[b] reuse of passwords is prohibited during the specified number of generations.