graphgrc

SCF - IAC-10.4 - Automated Support For Password Strength

Automated mechanisms exist to determine if password authenticators are sufficiently strong enough to satisfy organization-defined password length and complexity requirements.

Mapped framework controls

NIST 800-53

Control questions

Does the organization use automated mechanisms to determine if password authenticators are sufficiently strong enough to satisfy organization-defined password length and complexity requirements?