This is not the latest version of the STIG. This is provided for archival purposes. See the latest STIG.

The operating system must enforce the limit of three consecutive invalid logon attempts by a user during a 15-minute time period.

STIG ID: SRG-OS-000021-GPOS-00005  |  SRG: SRG-OS-000021 |  Severity: medium (CAT II)  |  CCI: CCI-000044 |  Vulnerability Id: V-203594

Vulnerability Discussion

By limiting the number of failed logon attempts, the risk of unauthorized system access via user password guessing, otherwise known as brute-force attacks, is reduced. Limits are imposed by locking the account.

Check

Verify that the operating system enforces the limit of three consecutive invalid logon attempts by a user during a 15-minute time period. If it does not, this is a finding.

Fix

Configure the operating system to enforce the limit of three consecutive invalid logon attempts by a user during a 15-minute time period.