Beyond CMMC Level 1
The free web app covers the 17 CMMC Level 1 practices. This requirement is part of the full NIST 800-171 set — get the desktop app to work on all 110 requirements with SPRS scoring. Previously saved data is shown read-only below, and your data always remains exportable in full.
Get the desktop appSecurity Requirements for 03.05.08 Password Reuse
Password lifetime restrictions do not apply to temporary passwords.
Assessment GuidanceExamine 0/8
How an assessor determines this requirement is met. Source: CMMC Assessment Guide – Level 2, Version 2.13 (NIST SP 800-171 Rev. 2).
Discussion
Individuals may not reuse their passwords for a defined period of time and a set number of passwords generated.
Examples
- Example 1
You explain in your company’s security policy that changing passwords regularly provides increased security by reducing the ability of adversaries to exploit stolen or purchased passwords over an extended period. You define how often individuals can reuse their passwords and the minimum number of password generations before reuse [a]. If a user
- Example 2
tries to reuse a password before the number of password generations has been exceeded, an error message is generated, and the user is required to enter a new password [b].
Assessment Methods
Not all of the evidence listed is required to meet this requirement — check the items your organization has collected.
- Personnel with authenticator management responsibilities
- Personnel with information security responsibilities
- System or network administrators
- System developers
- Mechanisms supporting or implementing password-based authenticator management capability
Potential Assessment Considerations
- How many generations of password changes need to take place before a password can be reused [a]?