Secure Controls Framework

1,534 controls across 34 domains

Source: SCF 2026.2About SCF
securecontrolsframework.com
Back to catalog
IAC-22IACIdentification & Authentication

Account Lockout

Description

Mechanisms exist to enforce a limit for consecutive invalid login attempts by a user during an organization-defined time period and automatically locks the account when the maximum number of unsuccessful attempts is exceeded.

Cross-Mappings

393 paths across 4 frameworks
NIST 800-531 mapping
AC-7
1.00
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
NIST 800-1711 mapping
3.1.8
1.00
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
CCI6 mappings
CCI-000043
1.00
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000044
1.00
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001423
1.00
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002236
1.00
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002237
1.00
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002238
1.00
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
STIG281 mappings
SV-104491r1_ruleSymantec ProxySG must be configured to enforce the limit of three consecutive invalid logon attempts by a user during a 15-minute time period.
1.00
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • DISA · V1R2 · disa_xccdf · related
SV-202019r960840_ruleThe network device must be configured to enforce the limit of three consecutive invalid logon attempts, after which time it must block any login attempt for 15 minutes.
1.00
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • DISA · V5R3 · disa_xccdf · related
SV-203594r958388_ruleThe operating system must enforce the limit of three consecutive invalid logon attempts by a user during a 15-minute time period.
1.00
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • DISA · 3 · disa_xccdf · related
SV-203698r958736_ruleThe operating system must automatically lock an account until the locked account is released by an administrator when three unsuccessful logon attempts in 15 minutes occur.
1.00
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • DISA · 3 · disa_xccdf · related
SV-204644r960840_ruleAAA Services must be configured to automatically lock user accounts after three consecutive invalid logon attempts within a 15-minute time period.
1.00
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • DISA · V2R2 · disa_xccdf · related
SV-204689r961368_ruleAAA Services must be configured to maintain locks on user accounts until released by an administrator.
1.00
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • DISA · V2R2 · disa_xccdf · related
SV-205455r960840_ruleThe Mainframe Product must enforce the limit of three consecutive invalid logon attempts by a user during a 15 minute time period.
1.00
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • DISA · 3 · disa_xccdf · related
SV-205547r961368_ruleThe Mainframe Product must automatically lock the account until the locked account is released by an administrator when three unsuccessful logon attempts in 15 minutes are exceeded.
1.00
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • DISA · 3 · disa_xccdf · related
SV-205629r958388_ruleWindows Server 2019 must have the number of allowed bad logon attempts configured to three or less.
1.00
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • DISA · 3 · disa_xccdf · related
SV-205630r958388_ruleWindows Server 2019 must have the period of time before the bad logon counter is reset configured to 15 minutes or greater.
1.00
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • DISA · 3 · disa_xccdf · related

+271 more (top 10 by confidence shown)

Control mappings provided by the Secure Controls Framework (SCF).

SCF

Powered by the Secure Controls Framework

The control catalog, cross-mappings, and STRM relationship data shown here are provided by the Secure Controls Framework (SCF), 2026.2. Every mapping is credited to SCF as the methodology, with the SCF reference and version stored alongside it.

© SCF Council, LLC. Secure Controls Framework content is free and shown here with attribution. securecontrolsframework.com · About SCF on STIGViewer