Overview

Security Requirements for 03.05.09 Temporary Passwords

Changing temporary passwords to permanent passwords immediately after system logon ensures that the necessary strength of the authentication mechanism is implemented at the earliest opportunity, reducing the susceptibility to authenticator compromises.

Evidence

  1. 03.05.09.a

    An immediate change to a permanent password is required when a temporary password is used for system logon