Publication of Default Password Usage Statistics, v1.0

Specifies requirements in accordance with the DHS CISA Secure-by-Design Pledge, published by the U.S. Dept of Homeland Security (DHS) Cybersecurity and Infrastructure Agency (CISA). Requires an organization to periodically publish statistics on its products that are still using default passwords, as well as progress of customer efforts to migrate away from default passwords.

Assessment Step

1
Publication of Default Password Usage Statistics (PublicationofDefaultPasswordUsageStatistics)
Does the organization periodically publish statistics on its products that are still using default passwords, as well as progress of customer efforts to migrate away from default passwords?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.

Conformance Criteria (1)

Publication of Default Password Usage Statistics
The organization must periodically publish statistics on its products that are still using default passwords, as well as progress of customer efforts to migrate away from default passwords.
Citation
SBDP
(doc)