
Look for profiles where the password has expired because the user has not changed it within the interval specified by the QPWDEXPITV system value (or PWDEXPITV inside the user profile).
If a user’s password is expired, it means that on next signing-on, the user has to change his or her password. This is a good indication that a profile is old and dormant. Profiles that are not kept current by their users are the most likely candidates for abuse by hackers or disgruntled employees.
|
PowerTech Recommendations Use the Compliance Monitor 'Profiles with Expired Password' report to audit all expired passwords. |
Profiles with Expired Password Report

Click to view expanded excerpt
from report
|
Relevant Standards:
COBIT DS5.3 - Identity Management All users (internal, external and temporary) and their activity on IT systems (business application, system operation, development and maintenance) should be uniquely identifiable. User access rights to systems and data should be in line with defined and documented business needs and job requirements.
COBIT DS5.4 – User Account Management Ensure that requesting, establishing, issuing, suspending, modifying and closing user accounts and related user privileges are addressed by user account management. An approval procedure outlining the data or system owner granting the access privileges should be included.
COBIT DS5.5 - Security Testing, Surveillance and Monitoring Ensure that IT security implementation is tested and monitored proactively. IT security should be reaccredited periodically to ensure the approved security level is maintained. A logging and monitoring function enables the early detection of unusual or abnormal activities that may need to be addressed.
ISO 27002 (17799) 11.2.3 - User Password Management The allocation of passwords should be controlled through a formal management process.
ISO 27002 (17799) 11.2.4 - Review of User Access Rights Management should review users' access rights at regular intervals using a formal process.
ISO 27002 (17799) 11.3.1 - Password Use Users would be required to follow good security practices in the selection and use of passwords, i.e. select quality passwords with sufficient minimum length, and that are free of consecutive identical, all-numeric or all-alphabetic characters. |