Skip to main content

๐Ÿ›ก๏ธ Oracle IAM Domain Password Policy has weak complexity requirements๐ŸŸข

  • Contextual name: ๐Ÿ›ก๏ธ Domain Password Policy has weak complexity requirements๐ŸŸข
  • ID: /ce/ca/oracle/iam/domain-password-policy-weak-complexity
  • Tags:
  • Policy Type: COMPLIANCE_POLICY
  • Policy Categories: SECURITY

Statsโ€‹

not available

Logicโ€‹

Similar Policiesโ€‹

  • Internal: dec-x-2e229fb4

Similar Internal Rulesโ€‹

RulePoliciesFlags
โœ‰๏ธ dec-x-2e229fb41

Descriptionโ€‹

Open File

Descriptionโ€‹

This policy identifies Oracle IAM domain password policies assigned to groups that do not require a minimum password length of at least 14 characters, at least one numeric character, or at least one special character.

Rationaleโ€‹

Password policies enforce baseline complexity for local IAM passwords. This policy does not evaluate the auto-created defaultPasswordPolicy. Non-default password policies apply only when they are assigned to an Oracle IAM group, and the policy then applies to users who are members of that group. Requiring a longer password, at least one numeric character, and at least one special character reduces the likelihood that users can choose overly weak passwords.

Impactโ€‹

Increasing password requirements can require users to change existing passwords at their next password reset or policy enforcement event. Communicate the change before applying it to production identity domains.

Auditโ€‹

This policy flags an Oracle IAM Domain Password Policy as INCOMPLIANT if it is assigned to at least one Oracle IAM group and one of the following is true:

... see more

Remediationโ€‹

Open File

Remediationโ€‹

Update Password Policy Requirementsโ€‹

Update each affected group password policy so passwords must be at least 14 characters long and must include at least one numeric character and at least one special character. If a group uses simplePasswordPolicy or standardPasswordPolicy, move the group to a custom password policy that meets these requirements.

From Oracle Cloud Consoleโ€‹
  1. Open Identity & Security.
  2. Select Domains.
  3. Open the affected identity domain.
  4. Open Settings, then select Password policy.
  5. For an affected custom password policy, edit the policy and configure:
    • Password length (minimum): 14 or greater.
    • Numeric (minimum): 1 or greater.
    • Special (minimum): 1 or greater.
  6. For a group assigned to simplePasswordPolicy or standardPasswordPolicy:
    • Create a custom password policy with the required settings.
    • Open the affected group.
    • Assign the group to the custom password policy.
  7. Save the changes.
  8. Confirm each affected group is assigned to a compliant custom password policy.

policy.yamlโ€‹

Open File

Linked Framework Sectionsโ€‹

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
๐Ÿ’ผ APRA CPG 234 โ†’ ๐Ÿ’ผ 4 Regulated entities would typically put in place processes to ensure that identities and credentials are issued, managed, verified, revoked and audited for authorised devices, users and software/processes.1111no data
๐Ÿ’ผ APRA CPG 234 โ†’ ๐Ÿ’ผ 5 The strength of identification and authentication would typically be commensurate with the impact should an identity be falsified. Common techniques for increasing the strength of identification and authentication include the use of strong password techniques (i.e. length, complexity, re-use limitations and frequency of change), utilisation of cryptographic techniques and increasing the number and type of authentication factors used. Authentication factors include something an individual: a. knows - for example, user IDs and passwords; b. has - for example, a security token or other devices in the personโ€™s possession used for the generation of one-time passwords; c. is - for example, retinal scans, hand scans, signature scans, digital signature, voice scans or other biometrics.44no data
๐Ÿ’ผ CIS Oracle v3.1.0 โ†’ ๐Ÿ’ผ 1.4 Ensure IAM password policy requires minimum length of 14 or greater - Level 1 (Automated)11no data
๐Ÿ’ผ Cloudaware Framework โ†’ ๐Ÿ’ผ Credential Lifecycle Management36no data
๐Ÿ’ผ FedRAMP High Security Controls โ†’ ๐Ÿ’ผ CM-7(1) Periodic Review (M)(H)1819no data
๐Ÿ’ผ FedRAMP Moderate Security Controls โ†’ ๐Ÿ’ผ CM-7(1) Periodic Review (M)(H)19no data
๐Ÿ’ผ ISO/IEC 27001:2013 โ†’ ๐Ÿ’ผ A.9.3.1 Use of secret authentication information44no data
๐Ÿ’ผ ISO/IEC 27001:2013 โ†’ ๐Ÿ’ผ A.9.4.3 Password management system22no data
๐Ÿ’ผ ISO/IEC 27001:2022 โ†’ ๐Ÿ’ผ 5.17 Authentication information44no data
๐Ÿ’ผ ISO/IEC 27001:2022 โ†’ ๐Ÿ’ผ 8.1 User end point devices1431no data
๐Ÿ’ผ ISO/IEC 27001:2022 โ†’ ๐Ÿ’ผ 8.9 Configuration management617no data
๐Ÿ’ผ NIST CSF v1.1 โ†’ ๐Ÿ’ผ PR.AC-1: Identities and credentials are issued, managed, verified, revoked, and audited for authorized devices, users and processes2237no data
๐Ÿ’ผ NIST CSF v1.1 โ†’ ๐Ÿ’ผ PR.AC-7: Users, devices, and other assets are authenticated (e.g., single-factor, multi-factor) commensurate with the risk of the transaction (e.g., individuals' security and privacy risks and other organizational risks)2428no data
๐Ÿ’ผ NIST CSF v2.0 โ†’ ๐Ÿ’ผ PR.AA-01: Identities and credentials for authorized users, services, and hardware are managed by the organization50no data
๐Ÿ’ผ NIST CSF v2.0 โ†’ ๐Ÿ’ผ PR.AA-03: Users, services, and hardware are authenticated102no data
๐Ÿ’ผ NIST CSF v2.0 โ†’ ๐Ÿ’ผ PR.AA-05: Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties199no data
๐Ÿ’ผ NIST SP 800-53 Revision 5 โ†’ ๐Ÿ’ผ CM-7(1) Least Functionality _ Periodic Review33no data
๐Ÿ’ผ PCI DSS v3.2.1 โ†’ ๐Ÿ’ผ 8.2.3 Passwords/passphrases must have complexity and strength.14no data
๐Ÿ’ผ PCI DSS v4.0.1 โ†’ ๐Ÿ’ผ 8.3.6 If passwords/passphrases are used as authentication factors to meet Requirement 8.3.1, they meet the minimum level of complexity.4no data
๐Ÿ’ผ PCI DSS v4.0 โ†’ ๐Ÿ’ผ 8.3.6 If passwords/passphrases are used as authentication factors to meet Requirement 8.3.1, they meet the minimum level of complexity.24no data
๐Ÿ’ผ UK Cyber Essentials โ†’ ๐Ÿ’ผ 2.1.2 Change any default or guessable account passwords34no data
๐Ÿ’ผ UK Cyber Essentials โ†’ ๐Ÿ’ผ 4.2.2 Use technical controls to manage the quality of passwords.34no data