{
    "control": "IA-5",
    "title": "Authenticator Management",
    "ccis": [
        {
            "cci": "CCI-000176",
            "definition": "Manage system authenticators by establishing initial authenticator content for authenticators issued by the organization."
        },
        {
            "cci": "CCI-000179",
            "definition": "The organization manages information system authenticators by establishing minimum lifetime restrictions for authenticators."
        },
        {
            "cci": "CCI-000180",
            "definition": "The organization manages information system authenticators by establishing maximum lifetime restrictions for authenticators."
        },
        {
            "cci": "CCI-000181",
            "definition": "The organization manages information system authenticators by establishing reuse conditions for authenticators."
        },
        {
            "cci": "CCI-000182",
            "definition": "Manage system authenticators by changing or refreshing authenticators in accordance with the organization-defined time period by authenticator type or when organization-defined events occur."
        },
        {
            "cci": "CCI-000183",
            "definition": "Manage system authenticators by protecting authenticator content from unauthorized disclosure."
        },
        {
            "cci": "CCI-000184",
            "definition": "Manage system authenticators by requiring individuals to take, and having devices implement, specific security controls to protect authenticators."
        },
        {
            "cci": "CCI-000185",
            "definition": "For public key-based authentication, validate certificates by constructing and verifying a certification path to an accepted trust anchor including checking certificate status information."
        },
        {
            "cci": "CCI-000186",
            "definition": "For public key-based authentication, enforce authorized access to the corresponding private key."
        },
        {
            "cci": "CCI-000187",
            "definition": "For public key-based authentication, map the authenticated identity to the account of the individual or group."
        },
        {
            "cci": "CCI-000192",
            "definition": "The information system enforces password complexity by the minimum number of upper case characters used."
        },
        {
            "cci": "CCI-000193",
            "definition": "The information system enforces password complexity by the minimum number of lower case characters used."
        },
        {
            "cci": "CCI-000194",
            "definition": "The information system enforces password complexity by the minimum number of numeric characters used."
        },
        {
            "cci": "CCI-000195",
            "definition": "The information system, for password-based authentication, when new passwords are created, enforces that at least an organization-defined number of characters are changed."
        },
        {
            "cci": "CCI-000196",
            "definition": "The information system, for password-based authentication, stores only cryptographically-protected passwords."
        },
        {
            "cci": "CCI-000197",
            "definition": "For password-based authentication, transmit passwords only over cryptographically-protected channels."
        },
        {
            "cci": "CCI-000198",
            "definition": "The information system enforces minimum password lifetime restrictions."
        },
        {
            "cci": "CCI-000199",
            "definition": "The information system enforces maximum password lifetime restrictions."
        },
        {
            "cci": "CCI-000200",
            "definition": "The information system prohibits password reuse for the organization-defined number of generations."
        },
        {
            "cci": "CCI-000201",
            "definition": "Protect authenticators commensurate with the security category of the information to which use of the authenticator permits access."
        },
        {
            "cci": "CCI-000202",
            "definition": "The organization ensures unencrypted static authenticators are not embedded in access scripts."
        },
        {
            "cci": "CCI-000203",
            "definition": "The organization ensures unencrypted static authenticators are not stored on function keys."
        },
        {
            "cci": "CCI-000204",
            "definition": "Defines the security controls required to manage the risk of compromise due to individuals having accounts on multiple systems."
        },
        {
            "cci": "CCI-000205",
            "definition": "The information system enforces minimum password length."
        },
        {
            "cci": "CCI-001544",
            "definition": "Manage system authenticators by ensuring that authenticators have sufficient strength of mechanism for their intended use."
        },
        {
            "cci": "CCI-001610",
            "definition": "Defines the time-period (by authenticator type) for changing/refreshing authenticators."
        },
        {
            "cci": "CCI-001611",
            "definition": "The organization defines the minimum number of special characters for password complexity enforcement."
        },
        {
            "cci": "CCI-001612",
            "definition": "The organization defines the minimum number of upper case characters for password complexity enforcement."
        },
        {
            "cci": "CCI-001613",
            "definition": "The organization defines the minimum number of lower case characters for password complexity enforcement."
        },
        {
            "cci": "CCI-001614",
            "definition": "The organization defines the minimum number of numeric characters for password complexity enforcement."
        },
        {
            "cci": "CCI-001615",
            "definition": "The organization defines the minimum number of characters that are changed when new passwords are created."
        },
        {
            "cci": "CCI-001616",
            "definition": "The organization defines minimum password lifetime restrictions."
        },
        {
            "cci": "CCI-001617",
            "definition": "The organization defines maximum password lifetime restrictions."
        },
        {
            "cci": "CCI-001618",
            "definition": "The organization defines the number of generations for which password reuse is prohibited."
        },
        {
            "cci": "CCI-001619",
            "definition": "The information system enforces password complexity by the minimum number of special characters used."
        },
        {
            "cci": "CCI-001621",
            "definition": "Implement organization-defined security controls to manage the risk of compromise due to individuals having accounts on multiple systems."
        },
        {
            "cci": "CCI-001980",
            "definition": "Manage system authenticators by verifying, as part of the initial authenticator distribution, the identity of the individual, group, role, service, or device receiving the authenticator."
        },
        {
            "cci": "CCI-001981",
            "definition": "Manage system authenticators by establishing administrative procedures for initial authenticator distribution."
        },
        {
            "cci": "CCI-001982",
            "definition": "The organization manages information system authenticators by establishing administrative procedures for lost/compromised authenticators."
        },
        {
            "cci": "CCI-001983",
            "definition": "The organization manages information system authenticators by establishing administrative procedures for damaged authenticators."
        },
        {
            "cci": "CCI-001984",
            "definition": "Manage system authenticators by establishing administrative procedures for revoking authenticators."
        },
        {
            "cci": "CCI-001985",
            "definition": "Manage system authenticators by implementing administrative procedures for initial authenticator distribution."
        },
        {
            "cci": "CCI-001986",
            "definition": "The organization manages information system authenticators by implementing administrative procedures for lost/compromised authenticators."
        },
        {
            "cci": "CCI-001987",
            "definition": "The organization manages information system authenticators by implementing administrative procedures for damaged authenticators."
        },
        {
            "cci": "CCI-001988",
            "definition": "Manage system authenticators by implementing administrative procedures for revoking authenticators."
        },
        {
            "cci": "CCI-001989",
            "definition": "The organization manages information system authenticators by changing default content of authenticators prior to information system installation."
        },
        {
            "cci": "CCI-001990",
            "definition": "Manage system authenticators by changing authenticators for group or role accounts when membership to those accounts changes."
        },
        {
            "cci": "CCI-001991",
            "definition": "The information system, for PKI-based authentication, implements a local cache of revocation data to support path discovery and validation in case of inability to access revocation information via the network."
        },
        {
            "cci": "CCI-001992",
            "definition": "The organization defines the personnel or roles responsible for authorizing the organization's registration authority accountable for the authenticator registration process."
        },
        {
            "cci": "CCI-001993",
            "definition": "The organization defines the registration authority accountable for the authenticator registration process."
        },
        {
            "cci": "CCI-001994",
            "definition": "The organization defines the types of and/or specific authenticators that are subject to the authenticator registration process."
        },
        {
            "cci": "CCI-001995",
            "definition": "The organization requires that the registration process, to receive organization-defined types of and/or specific authenticators, be conducted in person, or by a trusted third-party, before an organization-defined registration authority with authorization by organization-defined personnel or roles."
        },
        {
            "cci": "CCI-001996",
            "definition": "The organization defines the requirements required by the automated tools to determine if password authenticators are sufficiently strong."
        },
        {
            "cci": "CCI-001997",
            "definition": "The organization employs automated tools to determine if password authenticators are sufficiently strong to satisfy organization-defined requirements."
        },
        {
            "cci": "CCI-001998",
            "definition": "Require developers and installers of system components to provide unique authenticators or change default authenticators prior to delivery and installation."
        },
        {
            "cci": "CCI-001999",
            "definition": "The organization defines the external organizations to be coordinated with for cross-organization management of credentials."
        },
        {
            "cci": "CCI-002000",
            "definition": "The organization coordinates with organization-defined external organizations for cross-organization management of credentials."
        },
        {
            "cci": "CCI-002001",
            "definition": "Bind identities and authenticators dynamically using organization-defined binding rules."
        },
        {
            "cci": "CCI-002002",
            "definition": "The organization defines the token quality requirements to be employed by the information system mechanisms for token-based authentication."
        },
        {
            "cci": "CCI-002003",
            "definition": "The information system, for token-based authentication, employs mechanisms that satisfy organization-defined token quality requirements."
        },
        {
            "cci": "CCI-002004",
            "definition": "Defines the biometric quality requirements to be employed by the mechanisms for biometric-based authentication."
        },
        {
            "cci": "CCI-002005",
            "definition": "For biometric-based authentication, employ mechanisms that satisfy organization-defined biometric quality requirements."
        },
        {
            "cci": "CCI-002006",
            "definition": "Defines the time period after which the use of cached authenticators is prohibited."
        },
        {
            "cci": "CCI-002007",
            "definition": "Prohibit the use of cached authenticators after an organization-defined time period."
        },
        {
            "cci": "CCI-002008",
            "definition": "For PKI-based authentication, employs an organization-wide methodology for managing the content of PKI trust stores installed across all platforms including networks, operating systems, browsers, and applications."
        },
        {
            "cci": "CCI-002041",
            "definition": "The information system allows the use of a temporary password for system logons with an immediate change to a permanent password."
        },
        {
            "cci": "CCI-002042",
            "definition": "Manage system authenticators by protecting authenticator content from unauthorized modification."
        },
        {
            "cci": "CCI-002043",
            "definition": "The organization uses only FICAM-approved path discovery and validation products and services."
        },
        {
            "cci": "CCI-002365",
            "definition": "The organization manages information system authenticators by requiring individuals to take specific security safeguards to protect authenticators."
        },
        {
            "cci": "CCI-002366",
            "definition": "The organization manages information system authenticators by having devices implement specific security safeguards to protect authenticators."
        },
        {
            "cci": "CCI-002367",
            "definition": "The organization ensures unencrypted static authenticators are not embedded in applications."
        }
    ],
    "rules_mapped": 108,
    "rules": [
        {
            "rule": "V-221579",
            "stig_id": "DTBC-0037",
            "title": "Online revocation checks must be performed.",
            "severity": "medium",
            "benchmark": "Google Chrome Current Windows",
            "ccis": [
                "CCI-000185"
            ]
        },
        {
            "rule": "V-242415",
            "stig_id": "CNTR-K8-001160",
            "title": "Secrets in Kubernetes must not be stored as environment variables.",
            "severity": "high",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-000196",
                "CCI-004062"
            ]
        },
        {
            "rule": "V-220716",
            "stig_id": "WN10-00-000090",
            "title": "Accounts must be configured to require password expiration.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000199",
                "CCI-004066"
            ]
        },
        {
            "rule": "V-220743",
            "stig_id": "WN10-AC-000025",
            "title": "The maximum password age must be configured to 60 days or less.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000199",
                "CCI-004066"
            ]
        },
        {
            "rule": "V-220744",
            "stig_id": "WN10-AC-000030",
            "title": "The minimum password age must be configured to at least 1 day.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000198",
                "CCI-004066"
            ]
        },
        {
            "rule": "V-220745",
            "stig_id": "WN10-AC-000035",
            "title": "Passwords must, at a minimum, be 14 characters.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000205",
                "CCI-004066"
            ]
        },
        {
            "rule": "V-220746",
            "stig_id": "WN10-AC-000040",
            "title": "The built-in Microsoft password complexity filter must be enabled.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000192",
                "CCI-000193",
                "CCI-000194",
                "CCI-001619"
            ]
        },
        {
            "rule": "V-220747",
            "stig_id": "WN10-AC-000045",
            "title": "Reversible password encryption must be disabled.",
            "severity": "high",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000196",
                "CCI-004062"
            ]
        },
        {
            "rule": "V-220903",
            "stig_id": "WN10-PK-000005",
            "title": "The DoD Root CA certificates must be installed in the Trusted Root Store.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000185",
                "CCI-002470"
            ]
        },
        {
            "rule": "V-220904",
            "stig_id": "WN10-PK-000010",
            "title": "The External Root CA certificates must be installed in the Trusted Root Store on unclassified systems.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000185"
            ]
        },
        {
            "rule": "V-220905",
            "stig_id": "WN10-PK-000015",
            "title": "The DoD Interoperability Root CA cross-certificates must be installed in the Untrusted Certificates Store on unclassified systems.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000185",
                "CCI-002470"
            ]
        },
        {
            "rule": "V-220906",
            "stig_id": "WN10-PK-000020",
            "title": "The US DOD CCEB Interoperability Root CA cross-certificates must be installed in the Untrusted Certificates Store on unclassified systems.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000185",
                "CCI-002470"
            ]
        },
        {
            "rule": "V-220926",
            "stig_id": "WN10-SO-000110",
            "title": "Unencrypted passwords must not be sent to third-party SMB Servers.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000197"
            ]
        },
        {
            "rule": "V-220937",
            "stig_id": "WN10-SO-000195",
            "title": "The system must be configured to prevent the storage of the LAN Manager hash of passwords.",
            "severity": "high",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000196",
                "CCI-004062"
            ]
        },
        {
            "rule": "V-220952",
            "stig_id": "WN10-SO-000280",
            "title": "Passwords for enabled local Administrator accounts must be changed at least every 60 days.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000199",
                "CCI-004066"
            ]
        },
        {
            "rule": "V-253273",
            "stig_id": "WN11-00-000090",
            "title": "Accounts must be configured to require password expiration.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000199",
                "CCI-004066"
            ]
        },
        {
            "rule": "V-253301",
            "stig_id": "WN11-AC-000025",
            "title": "The maximum password age must be configured to 60 days or less.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000199",
                "CCI-004066"
            ]
        },
        {
            "rule": "V-253302",
            "stig_id": "WN11-AC-000030",
            "title": "The minimum password age must be configured to at least 1 day.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000198",
                "CCI-004066"
            ]
        },
        {
            "rule": "V-253303",
            "stig_id": "WN11-AC-000035",
            "title": "Passwords must, at a minimum, be 14 characters.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000205",
                "CCI-004066"
            ]
        },
        {
            "rule": "V-253304",
            "stig_id": "WN11-AC-000040",
            "title": "The built-in Microsoft password complexity filter must be enabled.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000192",
                "CCI-004066"
            ]
        },
        {
            "rule": "V-253305",
            "stig_id": "WN11-AC-000045",
            "title": "Reversible password encryption must be disabled.",
            "severity": "high",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000196",
                "CCI-004062"
            ]
        },
        {
            "rule": "V-253427",
            "stig_id": "WN11-PK-000005",
            "title": "The DoD Root CA certificates must be installed in the Trusted Root Store.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000185"
            ]
        },
        {
            "rule": "V-253428",
            "stig_id": "WN11-PK-000010",
            "title": "The External Root CA certificates must be installed in the Trusted Root Store on unclassified systems.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000185"
            ]
        },
        {
            "rule": "V-253450",
            "stig_id": "WN11-SO-000110",
            "title": "Unencrypted passwords must not be sent to third-party SMB Servers.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000197"
            ]
        },
        {
            "rule": "V-253461",
            "stig_id": "WN11-SO-000195",
            "title": "The system must be configured to prevent the storage of the LAN Manager hash of passwords.",
            "severity": "high",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000196",
                "CCI-004062"
            ]
        },
        {
            "rule": "V-253476",
            "stig_id": "WN11-SO-000280",
            "title": "Passwords for enabled local Administrator accounts must be changed at least every 60 days.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000199",
                "CCI-004066"
            ]
        },
        {
            "rule": "V-205645",
            "stig_id": "WN19-DC-000280",
            "title": "Windows Server 2019 domain controllers must have a PKI server certificate.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000185"
            ]
        },
        {
            "rule": "V-205646",
            "stig_id": "WN19-DC-000290",
            "title": "Windows Server 2019 domain Controller PKI certificates must be issued by the DoD PKI or an approved External Certificate Authority (ECA).",
            "severity": "high",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000185"
            ]
        },
        {
            "rule": "V-205647",
            "stig_id": "WN19-DC-000300",
            "title": "Windows Server 2019 PKI certificates associated with user accounts must be issued by a DoD PKI or an approved External Certificate Authority (ECA).",
            "severity": "high",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000185"
            ]
        },
        {
            "rule": "V-205648",
            "stig_id": "WN19-PK-000010",
            "title": "Windows Server 2019 must have the DoD Root Certificate Authority (CA) certificates installed in the Trusted Root Store.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000185",
                "CCI-002470"
            ]
        },
        {
            "rule": "V-205649",
            "stig_id": "WN19-PK-000020",
            "title": "Windows Server 2019 must have the DoD Interoperability Root Certificate Authority (CA) cross-certificates installed in the Untrusted Certificates Store on unclassified systems.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000185",
                "CCI-002470"
            ]
        },
        {
            "rule": "V-205650",
            "stig_id": "WN19-PK-000030",
            "title": "Windows Server 2019 must have the US DoD CCEB Interoperability Root CA cross-certificates in the Untrusted Certificates Store on unclassified systems.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000185",
                "CCI-002470"
            ]
        },
        {
            "rule": "V-205651",
            "stig_id": "WN19-SO-000350",
            "title": "Windows Server 2019 users must be required to enter a password to access private keys stored on the computer.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000186"
            ]
        },
        {
            "rule": "V-205652",
            "stig_id": "WN19-AC-000080",
            "title": "Windows Server 2019 must have the built-in Windows password complexity policy enabled.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000192",
                "CCI-000193",
                "CCI-000194",
                "CCI-001619",
                "CCI-004066"
            ]
        },
        {
            "rule": "V-205653",
            "stig_id": "WN19-AC-000090",
            "title": "Windows Server 2019 reversible password encryption must be disabled.",
            "severity": "high",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000196",
                "CCI-004062"
            ]
        },
        {
            "rule": "V-205654",
            "stig_id": "WN19-SO-000300",
            "title": "Windows Server 2019 must be configured to prevent the storage of the LAN Manager hash of passwords.",
            "severity": "high",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000196",
                "CCI-004062"
            ]
        },
        {
            "rule": "V-205655",
            "stig_id": "WN19-SO-000180",
            "title": "Windows Server 2019 unencrypted passwords must not be sent to third-party Server Message Block (SMB) servers.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000197"
            ]
        },
        {
            "rule": "V-205656",
            "stig_id": "WN19-AC-000060",
            "title": "Windows Server 2019 minimum password age must be configured to at least one day.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000198",
                "CCI-004066"
            ]
        },
        {
            "rule": "V-205657",
            "stig_id": "WN19-00-000020",
            "title": "Windows Server 2019 passwords for the built-in Administrator account must be changed at least every 60 days.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000199",
                "CCI-004066"
            ]
        },
        {
            "rule": "V-205658",
            "stig_id": "WN19-00-000210",
            "title": "Windows Server 2019 passwords must be configured to expire.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000199",
                "CCI-004066"
            ]
        },
        {
            "rule": "V-205659",
            "stig_id": "WN19-AC-000050",
            "title": "Windows Server 2019 maximum password age must be configured to 60 days or less.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000199",
                "CCI-004066"
            ]
        },
        {
            "rule": "V-205661",
            "stig_id": "WN19-00-000050",
            "title": "Windows Server 2019 manually managed application account passwords must be at least 14 characters in length.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000205",
                "CCI-004066"
            ]
        },
        {
            "rule": "V-205662",
            "stig_id": "WN19-AC-000070",
            "title": "Windows Server 2019 minimum password length must be configured to 14 characters.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000205",
                "CCI-004066"
            ]
        },
        {
            "rule": "V-254239",
            "stig_id": "WN22-00-000020",
            "title": "Windows Server 2022 passwords for the built-in Administrator account must be changed at least every 60 days.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000199",
                "CCI-004066"
            ]
        },
        {
            "rule": "V-254242",
            "stig_id": "WN22-00-000050",
            "title": "Windows Server 2022 manually managed application account passwords must be at least 14 characters in length.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000205",
                "CCI-004066"
            ]
        },
        {
            "rule": "V-254258",
            "stig_id": "WN22-00-000210",
            "title": "Windows Server 2022 passwords must be configured to expire.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000199",
                "CCI-004066"
            ]
        },
        {
            "rule": "V-254289",
            "stig_id": "WN22-AC-000050",
            "title": "Windows Server 2022 maximum password age must be configured to 60 days or less.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000199",
                "CCI-004066"
            ]
        },
        {
            "rule": "V-254290",
            "stig_id": "WN22-AC-000060",
            "title": "Windows Server 2022 minimum password age must be configured to at least one day.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000198",
                "CCI-004066"
            ]
        },
        {
            "rule": "V-254291",
            "stig_id": "WN22-AC-000070",
            "title": "Windows Server 2022 minimum password length must be configured to 14 characters.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000205",
                "CCI-004066"
            ]
        },
        {
            "rule": "V-254292",
            "stig_id": "WN22-AC-000080",
            "title": "Windows Server 2022 must have the built-in Windows password complexity policy enabled.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000192",
                "CCI-000193",
                "CCI-000194",
                "CCI-001619",
                "CCI-004066"
            ]
        },
        {
            "rule": "V-254293",
            "stig_id": "WN22-AC-000090",
            "title": "Windows Server 2022 reversible password encryption must be disabled.",
            "severity": "high",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000196",
                "CCI-004062"
            ]
        },
        {
            "rule": "V-254412",
            "stig_id": "WN22-DC-000280",
            "title": "Windows Server 2022 domain controllers must have a PKI server certificate.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000185"
            ]
        },
        {
            "rule": "V-254413",
            "stig_id": "WN22-DC-000290",
            "title": "Windows Server 2022 domain Controller PKI certificates must be issued by the DoD PKI or an approved External Certificate Authority (ECA).",
            "severity": "high",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000185"
            ]
        },
        {
            "rule": "V-254414",
            "stig_id": "WN22-DC-000300",
            "title": "Windows Server 2022 PKI certificates associated with user accounts must be issued by a DoD PKI or an approved External Certificate Authority (ECA).",
            "severity": "high",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000185"
            ]
        },
        {
            "rule": "V-254442",
            "stig_id": "WN22-PK-000010",
            "title": "Windows Server 2022 must have the DoD Root Certificate Authority (CA) certificates installed in the Trusted Root Store.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000185",
                "CCI-002470"
            ]
        },
        {
            "rule": "V-254443",
            "stig_id": "WN22-PK-000020",
            "title": "Windows Server 2022 must have the DoD Interoperability Root Certificate Authority (CA) cross-certificates installed in the Untrusted Certificates Store on unclassified systems.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000185",
                "CCI-002470"
            ]
        },
        {
            "rule": "V-254444",
            "stig_id": "WN22-PK-000030",
            "title": "Windows Server 2022 must have the US DOD CCEB Interoperability Root CA cross-certificates in the Untrusted Certificates Store on unclassified systems.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000185",
                "CCI-002470"
            ]
        },
        {
            "rule": "V-254462",
            "stig_id": "WN22-SO-000180",
            "title": "Windows Server 2022 unencrypted passwords must not be sent to third-party Server Message Block (SMB) servers.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000197"
            ]
        },
        {
            "rule": "V-254474",
            "stig_id": "WN22-SO-000300",
            "title": "Windows Server 2022 must be configured to prevent the storage of the LAN Manager hash of passwords.",
            "severity": "high",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000196",
                "CCI-004062"
            ]
        },
        {
            "rule": "V-254479",
            "stig_id": "WN22-SO-000350",
            "title": "Windows Server 2022 users must be required to enter a password to access private keys stored on the computer.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000186"
            ]
        },
        {
            "rule": "V-230229",
            "stig_id": "RHEL-08-010090",
            "title": "RHEL 8, for PKI-based authentication, must validate certificates by constructing a certification path (which includes status information) to an accepted trust anchor.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000185"
            ]
        },
        {
            "rule": "V-230230",
            "stig_id": "RHEL-08-010100",
            "title": "RHEL 8, for certificate-based authentication, must enforce authorized access to the corresponding private key.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000186"
            ]
        },
        {
            "rule": "V-230231",
            "stig_id": "RHEL-08-010110",
            "title": "RHEL 8 must encrypt all stored passwords with a FIPS 140-2 approved cryptographic hashing algorithm.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000196",
                "CCI-004062"
            ]
        },
        {
            "rule": "V-230232",
            "stig_id": "RHEL-08-010120",
            "title": "RHEL 8 must employ FIPS 140-2 approved cryptographic hashing algorithms for all stored passwords.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000196",
                "CCI-004062"
            ]
        },
        {
            "rule": "V-230233",
            "stig_id": "RHEL-08-010130",
            "title": "The RHEL 8 shadow password suite must be configured to use a sufficient number of hashing rounds.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000196",
                "CCI-004062"
            ]
        },
        {
            "rule": "V-230355",
            "stig_id": "RHEL-08-020090",
            "title": "RHEL 8 must map the authenticated identity to the user or group account for PKI-based authentication.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000187"
            ]
        },
        {
            "rule": "V-230357",
            "stig_id": "RHEL-08-020110",
            "title": "RHEL 8 must enforce password complexity by requiring that at least one uppercase character be used.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000192",
                "CCI-004066"
            ]
        },
        {
            "rule": "V-230358",
            "stig_id": "RHEL-08-020120",
            "title": "RHEL 8 must enforce password complexity by requiring that at least one lower-case character be used.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000193",
                "CCI-004066"
            ]
        },
        {
            "rule": "V-230359",
            "stig_id": "RHEL-08-020130",
            "title": "RHEL 8 must enforce password complexity by requiring that at least one numeric character be used.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000194",
                "CCI-004066"
            ]
        },
        {
            "rule": "V-230360",
            "stig_id": "RHEL-08-020140",
            "title": "RHEL 8 must require the maximum number of repeating characters of the same character class be limited to four when passwords are changed.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000195",
                "CCI-004066"
            ]
        },
        {
            "rule": "V-230361",
            "stig_id": "RHEL-08-020150",
            "title": "RHEL 8 must require the maximum number of repeating characters be limited to three when passwords are changed.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000195",
                "CCI-004066"
            ]
        },
        {
            "rule": "V-230362",
            "stig_id": "RHEL-08-020160",
            "title": "RHEL 8 must require the change of at least four character classes when passwords are changed.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000195",
                "CCI-004066"
            ]
        },
        {
            "rule": "V-230363",
            "stig_id": "RHEL-08-020170",
            "title": "RHEL 8 must require the change of at least 8 characters when passwords are changed.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000195",
                "CCI-004066"
            ]
        },
        {
            "rule": "V-230364",
            "stig_id": "RHEL-08-020180",
            "title": "RHEL 8 passwords must have a 24 hours/1 day minimum password lifetime restriction in /etc/shadow.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000198",
                "CCI-004066"
            ]
        },
        {
            "rule": "V-230365",
            "stig_id": "RHEL-08-020190",
            "title": "RHEL 8 passwords for new users or password changes must have a 24 hours/1 day minimum password lifetime restriction in /etc/login.defs.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000198",
                "CCI-004066"
            ]
        },
        {
            "rule": "V-230366",
            "stig_id": "RHEL-08-020200",
            "title": "RHEL 8 user account passwords must have a 60-day maximum password lifetime restriction.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000199",
                "CCI-004066"
            ]
        },
        {
            "rule": "V-230367",
            "stig_id": "RHEL-08-020210",
            "title": "RHEL 8 user account passwords must be configured so that existing passwords are restricted to a 60-day maximum lifetime.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000199",
                "CCI-004066"
            ]
        },
        {
            "rule": "V-230369",
            "stig_id": "RHEL-08-020230",
            "title": "RHEL 8 passwords must have a minimum of 15 characters.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000205",
                "CCI-004066"
            ]
        },
        {
            "rule": "V-230370",
            "stig_id": "RHEL-08-020231",
            "title": "RHEL 8 passwords for new users must have a minimum of 15 characters.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000205",
                "CCI-004066"
            ]
        },
        {
            "rule": "V-230375",
            "stig_id": "RHEL-08-020280",
            "title": "All RHEL 8 passwords must contain at least one special character.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-001619",
                "CCI-004066"
            ]
        },
        {
            "rule": "V-230376",
            "stig_id": "RHEL-08-020290",
            "title": "RHEL 8 must prohibit the use of cached authentications after one day.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-002007"
            ]
        },
        {
            "rule": "V-257826",
            "stig_id": "RHEL-09-215015",
            "title": "RHEL 9 must not have a File Transfer Protocol (FTP) server package installed.",
            "severity": "high",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000197",
                "CCI-000381"
            ]
        },
        {
            "rule": "V-258041",
            "stig_id": "RHEL-09-411010",
            "title": "RHEL 9 user account passwords for new users or password changes must have a 60-day maximum password lifetime restriction in /etc/login.defs.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000199",
                "CCI-004066"
            ]
        },
        {
            "rule": "V-258042",
            "stig_id": "RHEL-09-411015",
            "title": "RHEL 9 user account passwords must have a 60-day maximum password lifetime restriction.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000199",
                "CCI-004066"
            ]
        },
        {
            "rule": "V-258091",
            "stig_id": "RHEL-09-611010",
            "title": "RHEL 9 must ensure the password complexity module in the system-auth file is configured for three retries or less.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000192",
                "CCI-004066"
            ]
        },
        {
            "rule": "V-258097",
            "stig_id": "RHEL-09-611040",
            "title": "RHEL 9 must ensure the password complexity module is enabled in the password-auth file.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000192",
                "CCI-000193",
                "CCI-004066"
            ]
        },
        {
            "rule": "V-258099",
            "stig_id": "RHEL-09-611050",
            "title": "RHEL 9 password-auth must be configured to use a sufficient number of hashing rounds.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000196",
                "CCI-000803",
                "CCI-004062"
            ]
        },
        {
            "rule": "V-258100",
            "stig_id": "RHEL-09-611055",
            "title": "RHEL 9 system-auth must be configured to use a sufficient number of hashing rounds.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000196",
                "CCI-000803",
                "CCI-004062"
            ]
        },
        {
            "rule": "V-258101",
            "stig_id": "RHEL-09-611060",
            "title": "RHEL 9 must enforce password complexity rules for the root account.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000192",
                "CCI-000193",
                "CCI-000194",
                "CCI-000195",
                "CCI-000205",
                "CCI-001619",
                "CCI-004066"
            ]
        },
        {
            "rule": "V-258102",
            "stig_id": "RHEL-09-611065",
            "title": "RHEL 9 must enforce password complexity by requiring that at least one lowercase character be used.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000193",
                "CCI-004066"
            ]
        },
        {
            "rule": "V-258103",
            "stig_id": "RHEL-09-611070",
            "title": "RHEL 9 must enforce password complexity by requiring that at least one numeric character be used.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000194",
                "CCI-004066"
            ]
        },
        {
            "rule": "V-258104",
            "stig_id": "RHEL-09-611075",
            "title": "RHEL 9 passwords for new users or password changes must have a 24 hours minimum password lifetime restriction in /etc/login.defs.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000198",
                "CCI-004066"
            ]
        },
        {
            "rule": "V-258105",
            "stig_id": "RHEL-09-611080",
            "title": "RHEL 9 passwords must have a 24 hours minimum password lifetime restriction in /etc/shadow.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000198",
                "CCI-004066"
            ]
        },
        {
            "rule": "V-258107",
            "stig_id": "RHEL-09-611090",
            "title": "RHEL 9 passwords must be created with a minimum of 15 characters.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000205",
                "CCI-004066"
            ]
        },
        {
            "rule": "V-258109",
            "stig_id": "RHEL-09-611100",
            "title": "RHEL 9 must enforce password complexity by requiring that at least one special character be used.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001619",
                "CCI-004066"
            ]
        },
        {
            "rule": "V-258111",
            "stig_id": "RHEL-09-611110",
            "title": "RHEL 9 must enforce password complexity by requiring that at least one uppercase character be used.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000192",
                "CCI-004066"
            ]
        },
        {
            "rule": "V-258112",
            "stig_id": "RHEL-09-611115",
            "title": "RHEL 9 must require the change of at least eight characters when passwords are changed.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000195",
                "CCI-004066"
            ]
        },
        {
            "rule": "V-258113",
            "stig_id": "RHEL-09-611120",
            "title": "RHEL 9 must require the maximum number of repeating characters of the same character class be limited to four when passwords are changed.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000195",
                "CCI-004066"
            ]
        },
        {
            "rule": "V-258114",
            "stig_id": "RHEL-09-611125",
            "title": "RHEL 9 must require the maximum number of repeating characters be limited to three when passwords are changed.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000195",
                "CCI-004066"
            ]
        },
        {
            "rule": "V-258115",
            "stig_id": "RHEL-09-611130",
            "title": "RHEL 9 must require the change of at least four character classes when passwords are changed.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000195",
                "CCI-004066"
            ]
        },
        {
            "rule": "V-258116",
            "stig_id": "RHEL-09-611135",
            "title": "RHEL 9 must be configured so that user and group account administration utilities are configured to store only encrypted representations of passwords.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000196",
                "CCI-004062"
            ]
        },
        {
            "rule": "V-258117",
            "stig_id": "RHEL-09-611140",
            "title": "RHEL 9 must be configured to use the shadow file to store only encrypted representations of passwords.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000196",
                "CCI-004062"
            ]
        },
        {
            "rule": "V-258127",
            "stig_id": "RHEL-09-611190",
            "title": "RHEL 9, for PKI-based authentication, must enforce authorized access to the corresponding private key.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000186"
            ]
        },
        {
            "rule": "V-258131",
            "stig_id": "RHEL-09-631010",
            "title": "RHEL 9, for PKI-based authentication, must validate certificates by constructing a certification path (which includes status information) to an accepted trust anchor.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000185",
                "CCI-001991",
                "CCI-004068"
            ]
        },
        {
            "rule": "V-258132",
            "stig_id": "RHEL-09-631015",
            "title": "RHEL 9 must map the authenticated identity to the user or group account for PKI-based authentication.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000187"
            ]
        },
        {
            "rule": "V-258133",
            "stig_id": "RHEL-09-631020",
            "title": "RHEL 9 must prohibit the use of cached authenticators after one day.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-002007"
            ]
        },
        {
            "rule": "V-258231",
            "stig_id": "RHEL-09-671015",
            "title": "RHEL 9 must employ FIPS 140-3 approved cryptographic hashing algorithms for all stored passwords.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000196",
                "CCI-000803",
                "CCI-004062"
            ]
        },
        {
            "rule": "V-258233",
            "stig_id": "RHEL-09-671025",
            "title": "RHEL 9 pam_unix.so module must be configured in the password-auth file to use a FIPS 140-3 approved cryptographic hashing algorithm for system authentication.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000196",
                "CCI-004062"
            ]
        }
    ]
}