STIGhubSTIGhub
STIGsRMF ControlsCompare

STIGhub

A free tool to search and browse the entire DISA STIG library. Saves up to 75% in security compliance research time.

Navigation

  • Browse STIGs
  • Search
  • RMF Controls
  • Compare Versions

Resources

  • About
  • Release Notes
  • VPAT
  • DISA STIG Library
STIGs updated 6 hours ago
Powered by Pylon
© 2026 Beacon Cloud Solutions, Inc. All rights reserved.
← Back to Tri-Lab Operating System Stack (TOSS) 5 Security Technical Implementation Guide

V-282619

CAT II (Medium)

TOSS 5 must enforce a delay of at least four seconds between logon prompts following a failed logon attempt.

Rule ID

SV-282619r1200837_rule

STIG

Tri-Lab Operating System Stack (TOSS) 5 Security Technical Implementation Guide

Version

V1R1

CCIs

CCI-000366

Discussion

Increasing the time between a failed authentication attempt and reprompting to enter credentials helps to slow a single-threaded brute force attack.

Check Content

Verify TOSS 5 enforces a delay of at least four seconds between console logon prompts following a failed logon attempt using the following command:

$ grep -i fail_delay /etc/login.defs

FAIL_DELAY 4

If the value of "FAIL_DELAY" is not set to "4" or greater or the line is commented out, this is a finding.

Fix Text

Configure the TOSS 5 to enforce a delay of at least four seconds between logon prompts following a failed console logon attempt.

Modify the "/etc/login.defs" file to set the "FAIL_DELAY" parameter to 4 or greater:

FAIL_DELAY 4