CIS Controls CIS-5.2

Use unique passwords for all enterprise assets. Best practice implementation includes, at a minimum, an 8-character password for accounts using Multi-Factor Authentication (MFA) and a 14-character password for accounts not using MFA. 

Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
CIS-5.2 Use Unique Passwords mitigates T1110 Brute Force
Comments
Unique passwords and minimum password lengths, which directly reduce the effectiveness of brute-force attacks by increasing the number of possible password combinations and limiting the reuse of compromised credentials across systems. This makes online password guessing and offline password cracking more difficult and reduces the success of credential-stuffing attacks.
References
CIS-5.2 Use Unique Passwords mitigates T1110.001 Password Guessing
Comments
Enforced minimum password length increases the search space and reduces the effectiveness of password guessing.
References
CIS-5.2 Use Unique Passwords mitigates T1110.002 Password Cracking
Comments
Longer passwords materially increase the effort required to recover plaintext passwords from captured hashes or related material.
References
CIS-5.2 Use Unique Passwords mitigates T1110.003 Password Spraying
Comments
Unique, non-common passwords reduce success of spraying common passwords across many accounts.
References
CIS-5.2 Use Unique Passwords mitigates T1078.001 Default Accounts
Comments
Unique passwords reduce adversary use of default or vendor-provided account credentials.
References
CIS-5.2 Use Unique Passwords mitigates T1078.002 Domain Accounts
Comments
Domain accounts can span users, admins, and services; unique passwords reduce domain credential reuse and lateral reuse risk.
References
CIS-5.2 Use Unique Passwords mitigates T1078.003 Local Accounts
Comments
Unique local passwords reduce reuse of one compromised local account credential across multiple endpoints or servers.
References
CIS-5.2 Use Unique Passwords mitigates T1078 Valid Accounts
Comments
Unique passwords reduce credential reuse across systems and accounts, limiting adversary use of one compromised password to pivot through valid accounts.
References
CIS-5.2 Use Unique Passwords mitigates T1110.004 Credential Stuffing
Comments
This directly counters password overlap from breached credentials reused across personal, third-party, and enterprise accounts.
References
CIS-5.2 Use Unique Passwords mitigates T1078.004 Cloud Accounts
Comments
Unique passwords reduce cloud/SaaS credential overlap and lateral reuse risk
References