IA
Identification And Authentication
2
3.5.9
Allow temporary password use for system logons with an immediate change to a permanent password.
Users must change their temporary passwords the first time they log in. Temporary passwords usually follow a consistent style within an organization and can be more easily guessed than passwords created by the unique user. Example You are in charge of setting temporary passwords for your users. Users must change their temporary passwords to a permanent password the first time they log in.
Allow temporary password use for system logons with an immediate change to a permanent password.
Changing temporary passwords to permanent passwords immediately after system logon ensures that the necessary strength of the authentication mechanism is implemented at the earliest opportunity, reducing the susceptibility to authenticator compromises.
N/A
NIST SP 800-53 Rev 4 IA-5(1)
NIST SP 800-171 Rev 1 3.5.9
NIST CSF v1.1 PR.AC-1, PR.AC-6, PR.AC-7
IA.2.080.[a] an immediate change to a permanent password is required when a temporary password is used for system logon.