IA.L2-3.5.9 Temporary Passwords
Permit a temporary password for logon only where it must be changed to a permanent password immediately on use.
3
artefacts
1
held by a system
1
at each review
moderate
to go live
Identity provider / directory
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Configuration forcing change at first logon · Identity provider / directory
periodic reviewEvidence produced at each review
- Evidence of enforcement in account creation and reset workflows · Identity provider / directory
governing documentDocuments that govern the control
- Procedure for issuing temporary passwords · Policy repository / GRC workspace
First move
Start with the 1 of 3 artefacts that already live in a system (Identity provider / directory); keep the periodic reviews but log each one as a dated record with a named reviewer.
Common gaps auditors find
- Temporary passwords remain valid indefinitely
- Change at first logon not enforced by the system
- Predictable temporary password patterns
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetIA.L2-3.5.8 Password Reuse · IA.L2-3.5.10 Cryptographically-Protected Passwords