Control: 1.6 Ensure compliance with IBM Cloud password requirements
A strong password is a very important step towards account security and safety. Passwords should never be shared with anyone, and must follow the strong password requirements as follows -
- Password must contain at least one uppercase letter
- Password must contain at least one lowercase letter
- Password must contain at least one number
- Password must contain at least 8 characters
- Passwords should not be reused
- Password must only contain ASCII characters
- Password cannot contain spaces, or any of the special characters
- Ensure the usage of a password meter which coaches user to create a stronger password than the minimum
IBM Cloud automatically prevents the usage of any passwords that do not meet password requirements, when the users are created in IBMid system. When enterprises integrate through enterprise federation (using SAML), then enterprise identity system is responsible for enforcing password strength.
Run the control in your terminal:
powerpipe control run ibm_compliance.control.cis_v100_1_6
Snapshot and share results via Turbot Pipes:
powerpipe loginpowerpipe control run ibm_compliance.control.cis_v100_1_6 --share
This control uses a named query:
select guid as resource, 'info' as status, 'Manual verification required.' as reason, guidfrom ibm_account;