{"description": "ICS techniques mitigated by Password Policies, ATT&CK mitigation M0927 (v1.0)", "name": "Password Policies (M0927)", "domain": "ics-attack", "versions": {"layer": "4.5", "attack": "17", "navigator": "5.1.0"}, "techniques": [{"techniqueID": "T0892", "comment": "Applications and appliances that utilize default username and password should be changed immediately after the installation, and before deployment to a production environment.(Citation: CISA June 2013)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T0812", "comment": "Review vendor documents and security alerts for potentially unknown or overlooked default credentials within existing devices\n", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T0822", "comment": "Set and enforce secure password policies for accounts.\n", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T0886", "comment": "Enforce strong password requirements to prevent password brute force methods for lateral movement.\n", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T0859", "comment": "Applications and appliances that utilize default username and password should be changed immediately after the installation, and before deployment to a production environment. (Citation: CISA June 2013)\n", "score": 1, "color": "#66b1ff", "showSubtechniques": false}], "gradient": {"colors": ["#ffffff", "#66b1ff"], "minValue": 0, "maxValue": 1}, "legendItems": [{"label": "mitigated by Password Policies", "color": "#66b1ff"}]}