4.1.5.1 Ensure password policy is configured for enhanced security
Profile Applicability
- Enterprise Level 1
Description
Configure Google Workspace Password Policy with a more secure length and is enforced upon next sign-in to protect against the use of common password attacks.
Rationale
Strong password policies protect an organization by prohibiting the use of weak passwords.
Impact
The potential impact associated with implementation of this setting is dependent upon the existing password policies in place in the environment. For environments that have strong password policies in place, the impact will be minimal. For organizations that do not have strong password policies in place, enhancing the password policy may require users to change passwords, and adhere to more stringent requirements than they have been accustomed to.
Configuring passwords to expire at a 1 year mark ensures that users are not forced to change passwords so often that easily discerned patterns are used in the creation of the passwords. The day-to-day impact on users will be that they have to manage fewer passwords changing on a frequent basis.
NOTE: Password should be changed immediately on any indication of system compromise, when a user role changes, and when a user leaves the organization.
Audit
To verify this setting via the Google Workspace Admin Console:
- Log in to
https://admin.google.comas an administrator - Select
Security - Select
Password management - Under
Strength, ensureEnforce strong passwordsischecked - Under
Length, ensureMinimum Lengthis set to14+ - Under
Strength and Length enforcement, ensureEnforce password policy at next sign-inis set tochecked - Under
Reuse, ensureAllow password reuseisunchecked - Under
Expiration, ensurePassword reset frequencyis set to365 Days
Remediation
To configure this setting via the Google Workspace Admin Console:
- Log in to
https://admin.google.comas an administrator - Select
Security - Select
Password management - Under
Strength, setEnforce strong passwordstochecked - Under
Length, setMinimum Lengthto14or greater - Under
Strength and Length enforcement, setEnforce password policy at next sign-inischecked - Under
Reuse, setAllow password reusetounchecked - Under
Expiration, setPassword reset frequencyto365 Days - Select
Save
Default Value
Enforce strong passwordischeckedMinimum lengthis8Maximum lengthis100Enforce password policy at next sign-inisnot checkedAllow password reuseisnot checkedExpirationisNever expires
CIS Controls
| Controls Version | Control | IG 1 | IG 2 | IG 3 |
|---|---|---|---|---|
| v8 | 5.2 Use Unique Passwords | x | x | x |
| v7 | 4.4 Use Unique Passwords | x | x |