HomeControl Library › 3.5.9
3.5 Identification & Authentication1 ptPOA&M-eligible

3.5.9 — Force change of temporary passwords

Allow temporary password use for system logons with an immediate change to a permanent password.

Temp passwords must be changed at first login.

What it actually means

When you issue a temporary password (new hire, reset), the system must force the user to change it to a permanent one at first use — so temp credentials don't linger.

Pass or fail — an assessor needs a "yes" to each

What to have ready

Where teams trip up

See where this control puts your score

Run all 110 requirements free in about 10 minutes.

Calculate your SPRS score →

Connected requirements

← Back to the Control Library