UCF STIG Viewer Logo

The network device must enforce the limit of three consecutive invalid logon attempts by a user during a 15-minute time period.


Overview

Finding ID Version Rule ID IA Controls Severity
V-55055 SRG-APP-000065-NDM-000214 SV-69301r1_rule Medium
Description
By limiting the number of failed login attempts, the risk of unauthorized system access via user password guessing, otherwise known as brute-forcing, is reduced.
STIG Date
Network Device Management Security Requirements Guide 2017-07-07

Details

Check Text ( C-55677r1_chk )
Determine if the network device is either configured to enforce the limit of three consecutive invalid logon attempts by a user during a 15-minute time period or configured to use an authentication server which would perform this function. If the limit of three consecutive invalid logon attempts by a user during a 15-minute time period is not enforced, this is a finding.
Fix Text (F-59921r1_fix)
Configure the network device or its associated authentication server to enforce the limit of three consecutive invalid logon attempts by a user during a 15-minute time period.