Use unique passwords for all enterprise assets. Best practice implementation includes, at a minimum, an 8-character password for accounts using Multi-Factor Authentication (MFA) and a 14-character password for accounts not using MFA.
| Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
|---|---|---|---|---|---|
| CIS-5.2 | Use Unique Passwords | mitigates | T1110 | Brute Force |
Comments
Unique passwords and minimum password lengths, which directly reduce the effectiveness of brute-force attacks by increasing the number of possible password combinations and limiting the reuse of compromised credentials across systems. This makes online password guessing and offline password cracking more difficult and reduces the success of credential-stuffing attacks.
References
|
| CIS-5.2 | Use Unique Passwords | mitigates | T1110.001 | Password Guessing |
Comments
Enforced minimum password length increases the search space and reduces the effectiveness of password guessing.
References
|
| CIS-5.2 | Use Unique Passwords | mitigates | T1110.002 | Password Cracking |
Comments
Longer passwords materially increase the effort required to recover plaintext passwords from captured hashes or related material.
References
|
| CIS-5.2 | Use Unique Passwords | mitigates | T1110.003 | Password Spraying |
Comments
Unique, non-common passwords reduce success of spraying common passwords across many accounts.
References
|
| CIS-5.2 | Use Unique Passwords | mitigates | T1078.001 | Default Accounts |
Comments
Unique passwords reduce adversary use of default or vendor-provided account credentials.
References
|
| CIS-5.2 | Use Unique Passwords | mitigates | T1078.002 | Domain Accounts |
Comments
Domain accounts can span users, admins, and services; unique passwords reduce domain credential reuse and lateral reuse risk.
References
|
| CIS-5.2 | Use Unique Passwords | mitigates | T1078.003 | Local Accounts |
Comments
Unique local passwords reduce reuse of one compromised local account credential across multiple endpoints or servers.
References
|
| CIS-5.2 | Use Unique Passwords | mitigates | T1078 | Valid Accounts |
Comments
Unique passwords reduce credential reuse across systems and accounts, limiting adversary use of one compromised password to pivot through valid accounts.
References
|
| CIS-5.2 | Use Unique Passwords | mitigates | T1110.004 | Credential Stuffing |
Comments
This directly counters password overlap from breached credentials reused across personal, third-party, and enterprise accounts.
References
|
| CIS-5.2 | Use Unique Passwords | mitigates | T1078.004 | Cloud Accounts |
Comments
Unique passwords reduce cloud/SaaS credential overlap and lateral reuse risk
References
|