NIST 800-171 · Identification and Authentication

Requirement 3.5.7

SPRS weight
SPRS weight: 1
POA&M eligibility
POA&M-eligible
Assessment objectives
4 assessment objectives

Official requirement text

Enforce a minimum password complexity and change of characters when new passwords are created.

Assessment objectives

Assessors don’t evaluate the requirement as one sentence; they walk these objectives one by one. Each must be met for the requirement to score.

  1. 3.5.7[a]password complexity requirements are defined.
  2. 3.5.7[b]password change of character requirements are defined.
  3. 3.5.7[c]minimum password complexity requirements as defined are enforced when new passwords are created.
  4. 3.5.7[d]minimum password change of character requirements as defined are enforced when new passwords are created.

Inside Valontir, this requirement carries a full plain-English guide: what it asks in normal words, what good looks like in a small shop, the evidence an assessor accepts, the common gaps that cost points, and a plain reading of every assessment objective shown above. See it in a demo.

NIST 800-171 3.5.7 explained — Identification and Authentication | Valontir