User password set programmatically

Overview

As a best practice, the creation of a user's password should be managed by the platform. Setting a password programmatically increases security risk and, in most circumstances, isn't required.

Business Impact

Increased risk of data breaches, financial loss, and reputational harm. Eroding customer trust and confidence.

Resources

Uncommon

Incidence

How common is this issue?
5%2%
arrow down3%
lower

Exposure

How long do organizations remain exposed before fixing the problem?
1 year3 months
arrow down80%
shorter
BenchmarkWith Clayton

Frameworks

TrustediconSecureiconData SecurityiconUse of EncryptioniconA04:2021 – Insecure Designicon