NIST 800-53 Rev 5

424 controls available

AC-7lowmoderatehigh

Unsuccessful Logon Attempts

Access Control

Control Statement

Enforce a limit of {{ insert: param, ac-07_odp.01 }} consecutive invalid logon attempts by a user during a {{ insert: param, ac-07_odp.02 }} ; and Automatically {{ insert: param, ac-07_odp.03 }} when the maximum number of unsuccessful attempts is exceeded.

Discussion

The need to limit unsuccessful logon attempts and take subsequent action when the maximum number of attempts is exceeded applies regardless of whether the logon occurs via a local or network connection. Due to the potential for denial of service, automatic lockouts initiated by systems are usually temporary and automatically release after a predetermined, organization-defined time period. If a delay algorithm is selected, organizations may employ different algorithms for different components of the system based on the capabilities of those components. Responses to unsuccessful logon attempts may be implemented at the operating system and the application levels. Organization-defined actions that may be taken when the number of allowed consecutive invalid logon attempts is exceeded include prompting the user to answer a secret question in addition to the username and password, invoking a lockdown mode with limited user capabilities (instead of full lockout), allowing users to only logon from specified Internet Protocol (IP) addresses, requiring a CAPTCHA to prevent automated attacks, or applying user profiles such as location, time of day, IP address, device, or Media Access Control (MAC) address. If automatic system lockout or execution of a delay algorithm is not implemented in support of the availability objective, organizations consider a combination of other actions to help prevent brute force attacks. In addition to the above, organizations can prompt users to respond to a secret question before the number of allowed unsuccessful logon attempts is exceeded. Automatically unlocking an account after a specified period of time is generally not permitted. However, exceptions may be required based on operational mission or need.

Framework
NIST SP 800-53 Rev 5
Family
Access Control
Baselines
low, moderate, high

Related Frameworks

7 paths across 2 frameworks
NIST 800-1711 mapping
3.1.8
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
CCI6 mappings
CCI-000043
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000044
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001423
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002236
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002237
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002238
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent

Related STIGs

178 STIGs reach this control through 16 CCIs. Expand a row to see the responsible NICE and O*NET roles.

Operating System — Desktop

7 STIGs

Operating System — Server

43 STIGs
Oracle Linux 8 Security Technical Implementation Guide
V2R82026-02-1318 of 375 findings match
Show 35 more STIGs in this category →
Oracle Linux 9 Security Technical Implementation Guide
V1R52026-02-179 of 448 findings match
Anduril NixOS Security Technical Implementation Guide
V1R22025-08-191 of 103 findings match
IBM AIX 7.x Security Technical Implementation Guide
V3R22026-02-061 of 283 findings match
IBM AIX 7.x Security Technical Implementation Guide
32024-08-161 of 283 findings match
Solaris 11 X86 Security Technical Implementation Guide
V3R52026-02-191 of 216 findings match

Operating System — Mainframe

10 STIGs
IBM z/OS TSS Security Technical Implementation Guide
V9R82026-03-093 of 230 findings match
Mainframe Product Security Requirements Guide
V3R42025-09-102 of 194 findings match
Mainframe Product Security Requirements Guide
32024-12-052 of 193 findings match
IBM z/OS ACF2 Security Technical Implementation Guide
V9R82026-03-091 of 225 findings match
Show 2 more STIGs in this category →
IBM z/OS RACF Security Technical Implementation Guide
V9R82026-03-091 of 222 findings match

Operating System — Mobile

36 STIGs
Show 28 more STIGs in this category →

Network Device

46 STIGs
AAA Services Security Requirements Guide
V2R22024-12-042 of 77 findings match
Cisco ACI NDM Security Technical Implementation Guide
V1R22025-12-111 of 26 findings match
Show 38 more STIGs in this category →
Cisco ISE NDM Security Technical Implementation Guide
V2R32025-12-111 of 53 findings match
Network Device Management Security Requirements Guide
V5R32025-02-111 of 104 findings match
Network Device Management Security Requirements Guide
V5R42025-09-101 of 105 findings match
RUCKUS ICX NDM Security Technical Implementation Guide
V1R12025-05-281 of 25 findings match

Web / Application Server

3 STIGs

Virtualization / Container

16 STIGs
Container Platform Security Requirements Guide
V2R42025-09-102 of 188 findings match
Container Platform Security Requirements Guide
22025-05-152 of 187 findings match
Show 8 more STIGs in this category →
Virtual Machine Manager Security Requirements Guide
22024-12-062 of 193 findings match
Virtual Machine Manager Security Requirements Guide
V2R32025-09-102 of 198 findings match

Cloud / Identity Service

3 STIGs

Endpoint Security Management

13 STIGs
Central Log Server Security Requirements Guide
V3R42026-02-122 of 127 findings match
Central Log Server Security Requirements Guide
32024-12-042 of 125 findings match
HYCU Protege Security Technical Implementation Guide
V1R22026-03-041 of 55 findings match
Show 5 more STIGs in this category →
ISEC7 Sphere Security Technical Implementation Guide
V3R12024-08-201 of 34 findings match

Productivity Application

1 STIG