Rule ID
SV-202019r960840_rule
Version
V5R4
CCIs
CCI-000044
By limiting the number of failed login attempts, the risk of unauthorized system access via user password guessing, otherwise known as brute-forcing, is reduced.
Review the device configuration to verify that it enforces the limit of three consecutive invalid logon attempts. If the device is not configured to enforce the limit of three consecutive invalid logon attempts, this is a finding.
Configure the network device to enforce the limit of three consecutive invalid logon attempts during a 15-minute time period.