Overview

Security Requirements for 03.05.08 Password Reuse

Password lifetime restrictions do not apply to temporary passwords.

Assessment GuidanceExamine 0/8

How an assessor determines this requirement is met. Source: CMMC Assessment Guide – Level 2, Version 2.13 (NIST SP 800-171 Rev. 2).

Discussion

Individuals may not reuse their passwords for a defined period of time and a set number of passwords generated.

Examples

  1. Example 1

    You explain in your company’s security policy that changing passwords regularly provides increased security by reducing the ability of adversaries to exploit stolen or purchased passwords over an extended period. You define how often individuals can reuse their passwords and the minimum number of password generations before reuse [a]. If a user

  2. Example 2

    tries to reuse a password before the number of password generations has been exceeded, an error message is generated, and the user is required to enter a new password [b].

Assessment Methods

Examine
The process of reviewing, inspecting, observing, studying, or analyzing assessment objects (e.g., policies, procedures, plans, system designs, mechanisms) to facilitate understanding, achieve clarification, or obtain evidence.Example: An assessor reads the access control policy and inspects system configuration settings to confirm they match.

Not all of the evidence listed is required to meet this requirement — check the items your organization has collected.

Interview
The process of holding discussions with individuals or groups within an organization to facilitate understanding, achieve clarification, or identify the location of evidence.Example: An assessor asks a system administrator to describe how user accounts are approved, reviewed, and disabled.
  • Personnel with authenticator management responsibilities
  • Personnel with information security responsibilities
  • System or network administrators
  • System developers
Test
The process of exercising assessment objects (e.g., activities, mechanisms) under specified conditions to compare actual behavior with expected behavior.Example: An assessor attempts to sign in with a disabled account to confirm that access is denied.
  • Mechanisms supporting or implementing password-based authenticator management capability

Potential Assessment Considerations

  • How many generations of password changes need to take place before a password can be reused [a]?

Key References

NIST SP 800-171 Rev. 2 3.5.8

Evidence

  1. 03.05.08.a

    The number of generations during which a password cannot be reused is specified

  1. 03.05.08.b

    Reuse of passwords is prohibited during the specified number of generations