HomeControl Library › 3.5.8
3.5 Identification & Authentication1 ptPOA&M-eligible

3.5.8 — Block password reuse

Prohibit password reuse for a specified number of generations.

Users can't recycle their recent passwords.

What it actually means

Stop users from cycling back to an old password. Configure password history in your identity provider so a defined number of prior passwords can't be reused.

Pass or fail — an assessor needs a "yes" to each

What to have ready

Where teams trip up

See where this control puts your score

Run all 110 requirements free in about 10 minutes.

Calculate your SPRS score →

Connected requirements

← Back to the Control Library