Microsoft Windows Server 2016 STIG Version Comparison
Microsoft Windows Server 2016 Security Technical Implementation Guide
Comparison
There are 2 differences between versions v2 r7 (Nov. 9, 2023) (the "left" version) and v2 r9 (Nov. 15, 2024) (the "right" version).
Check WN16-00-000060 was changed between these two versions. Green, underlined text was added, red, struck-out text was removed.
The regular view of the left check and right check may be easier to read.
Text Differences
Title
Manually managed application account passwords must be at least 15 14 characters in length.
Check Content
Determine if manually managed application/service accounts exist. If none exist, this is NA. Verify the organization has a policy to ensure passwords for manually managed application/service accounts are at least 15 14 characters in length. If such a policy does not exist or has not been implemented, this is a finding.
Discussion
Application/service account passwords must be of sufficient length to prevent being easily cracked. Application/service accounts that are manually managed must have passwords at least 15 14 characters in length.
Fix
Establish a policy that requires application/service account passwords that are manually managed to be at least 15 14 characters in length. Ensure the policy is enforced.