STIGQter STIGQter: STIG Summary: NetApp ONTAP DSC 9.x Security Technical Implementation Guide Version: 2 Release: 4 Benchmark Date: 01 Jul 2026:

ONTAP must enforce a minimum 15-character password length.

DISA Rule

SV-246951r1015270_rule

Vulnerability Number

V-246951

Group Title

SRG-APP-000164-NDM-000252

Rule Version

NAOT-IA-000005

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the minimum password length for the role admin to 15 with "security login role config modify -vserver <vserver name> -role admin -passwd-minlength 15".

Check Contents

Use "security login role config show -role admin -fields passwd-minlength" to see the minimum password length for the role admin.

If ONTAP is not configured to enforce a minimum 15-character password length, this is a finding.

Vulnerability Number

V-246951

Documentable

False

Rule Version

NAOT-IA-000005

Severity Override Guidance

Use "security login role config show -role admin -fields passwd-minlength" to see the minimum password length for the role admin.

If ONTAP is not configured to enforce a minimum 15-character password length, this is a finding.

Check Content Reference

M

Target Key

5415