Strong Password Policy
Definition
Modifying system configuration to increase password strength.
How it works
Password strength guidelines include increasing password length, permitting passwords that contain ASCII or Unicode characters, and requiring systems to screen new passwords against lists of commonly used or compromised passwords.
Considerations
Extremely complex password requirements may lead users to saving passwords in text files or picking obvious passwords that meet the policy.
Artifact Relationships:
This defensive technique is related to specific artifacts. Click the artifact node for more information.
Technique Subclasses
There are 2 techniques in this category, Strong Password Policy.
| Name | ID | Definition | Synonyms |
|---|---|---|---|
| Strong Password Policy | D3-SPP | Modifying system configuration to increase password strength. | |
| - Change Default Password | D3-CDP | Changing the default password means replacing the factory-set credentials with a strong, unique password before the device is deployed, preventing unauthorized access. |
Related ATT&CK Techniques:
These offensive techniques are determined related because of the way this defensive technique,, , , and .
References
The following references were used to develop the Strong Password Policy knowledge-base article.
(Note: the consideration of references does not imply specific functionality exists in an offering.)