| name | Password Management (03.05.07)_password-management |
| description | Maintain a list of commonly-used, expected, or compromised passwords, and update the list [organization-defined] and when organizational passwords ... |
| category | authentication |
| version | 3.0 |
| author | cyberstrike-official |
| tags | ["nist","sp800-171","rev3","password management (03-05-07)","family-03.05","cui-protection","cmmc"] |
| tech_stack | ["aws","azure","active-directory","linux","windows"] |
| cwe_ids | ["CWE-287"] |
| chains_with | [] |
| prerequisites | [] |
| severity_boost | {} |
Password Management (03.05.07) Password Management
High-Level Description
Family: Identification and Authentication
Framework: NIST SP 800-171 Rev 3
Applicability: Systems processing, storing, or transmitting CUI
Maintain a list of commonly-used, expected, or compromised passwords, and update the list [organization-defined] and when organizational passwords are suspected to have been compromised.
Verify that passwords are not found on the list of commonly used, expected, or compromised passwords when users create or update passwords.
Transmit passwords only over cryptographically protected channels.
Store passwords in a cryptographically protected form.
Select a new password upon first use after account recovery.
Enforce the following composition and complexity rules for passwords: [organization-defined].
What to Check
How to Test
Step 1: Review System Security Plan
Examine the SSP for Password Management (03.05.07) implementation description and responsible parties.
Step 2: Assess Implementation
# Verify security controls protecting CUI
# Check access controls, encryption, monitoring as applicable
# For Linux systems:
ls -la /etc/security/ 2>/dev/null
grep -r "CUI\|controlled" /etc/security/ 2>/dev/null
# For cloud:
# Use cloud-audit-mcp tools to assess posture
Step 3: CMMC Assessment Validation
Verify this requirement passes CMMC Level 2 assessment methodology per SP 800-171A Rev 3.
Tools
| Tool | Purpose | Usage |
|---|
| cloud-audit-mcp | Assess cloud CUI environment | cloud_audit_* tools |
| Manual Review | SSP and POA&M review | Documentation analysis |
Remediation Guide
Requirement Statement
Maintain a list of commonly-used, expected, or compromised passwords, and update the list [organization-defined] and when organizational passwords are suspected to have been compromised.
Verify that passwords are not found on the list of commonly used, expected, or compromised passwords when users create or update passwords.
Transmit passwords only over cryptographically protected channels.
Store passwords in a cryptographically protected form.
Select a new password upon first use after account recovery.
Enforce the following composition and complexity rules for passwords: [organization-defined].