SBD-ALERT-7—Eliminating Default Passwords
>Control Description
CISA Secure by Design Alert (December 15, 2023): Technology manufacturers should eliminate default passwords from their products entirely. Products should ship with unique-per-instance credentials or require credential creation during initial setup. Manufacturers should audit existing products for default credentials and provide migration paths for deployed systems still using default passwords.
>Related Controls
Ask AI
Configure your API key to use AI features.