{
    "control": "AC-7",
    "title": "Unsuccessful Logon Attempts",
    "ccis": [
        {
            "cci": "CCI-000043",
            "definition": "Defines the maximum number of consecutive invalid logon attempts to the information system by a user during an organization-defined time period."
        },
        {
            "cci": "CCI-000044",
            "definition": "Enforce the organization-defined limit of consecutive invalid logon attempts by a user during the organization-defined time period."
        },
        {
            "cci": "CCI-001423",
            "definition": "Defines the time period in which the organization-defined maximum number of consecutive invalid logon attempts occur."
        },
        {
            "cci": "CCI-002236",
            "definition": "Defines the time period the information system will automatically lock the account or node when the maximum number of unsuccessful logon attempts is exceeded."
        },
        {
            "cci": "CCI-002237",
            "definition": "Defines the delay algorithm to delay the next logon prompt when the maximum number of unsuccessful logon attempts is exceeded."
        },
        {
            "cci": "CCI-002238",
            "definition": "Automatically lock the account or node for either an organization-defined time period, until the locked account or node is released by an administrator, or delays the next logon prompt according to the organization-defined delay algorithm when the maximum number of unsuccessful logon attempts is exceeded."
        },
        {
            "cci": "CCI-002239",
            "definition": "Defines the mobile devices that are to be purged or wiped after an organization-defined number of consecutive, unsuccessful device logon attempts."
        },
        {
            "cci": "CCI-002240",
            "definition": "Defines the purging or wiping requirements and techniques to be used on organization-defined mobile devices after an organization-defined number of consecutive, unsuccessful device logon attempts."
        },
        {
            "cci": "CCI-002241",
            "definition": "Defines the number of consecutive, unsuccessful device logon attempts after which the organization-defined mobile devices will be purged or wiped."
        },
        {
            "cci": "CCI-002242",
            "definition": "Purge or wipe information from organization-defined mobile devices based on organization-defined purging or wiping requirements and techniques after an organization-defined number of consecutive, unsuccessful device logon attempts."
        }
    ],
    "rules_mapped": 40,
    "rules": [
        {
            "rule": "V-220739",
            "stig_id": "WN10-AC-000005",
            "title": "Windows 10 account lockout duration must be configured to 15 minutes or greater.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-002238"
            ]
        },
        {
            "rule": "V-220740",
            "stig_id": "WN10-AC-000010",
            "title": "The number of allowed bad logon attempts must be configured to 3 or less.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000044"
            ]
        },
        {
            "rule": "V-220741",
            "stig_id": "WN10-AC-000015",
            "title": "The period of time before the bad logon counter is reset must be configured to 15 minutes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000044",
                "CCI-002238"
            ]
        },
        {
            "rule": "V-253297",
            "stig_id": "WN11-AC-000005",
            "title": "Windows 11 account lockout duration must be configured to 15 minutes or greater.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-002238"
            ]
        },
        {
            "rule": "V-253298",
            "stig_id": "WN11-AC-000010",
            "title": "The number of allowed bad logon attempts must be configured to three or less.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000044"
            ]
        },
        {
            "rule": "V-253299",
            "stig_id": "WN11-AC-000015",
            "title": "The period of time before the bad logon counter is reset must be configured to 15 minutes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000044"
            ]
        },
        {
            "rule": "V-253445",
            "stig_id": "WN11-SO-000075",
            "title": "The required legal notice must be configured to display before console logon.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000044",
                "CCI-000048",
                "CCI-000050"
            ]
        },
        {
            "rule": "V-205629",
            "stig_id": "WN19-AC-000020",
            "title": "Windows Server 2019 must have the number of allowed bad logon attempts configured to three or less.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000044"
            ]
        },
        {
            "rule": "V-205630",
            "stig_id": "WN19-AC-000030",
            "title": "Windows Server 2019 must have the period of time before the bad logon counter is reset configured to 15 minutes or greater.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000044",
                "CCI-002238"
            ]
        },
        {
            "rule": "V-205795",
            "stig_id": "WN19-AC-000010",
            "title": "Windows Server 2019 account lockout duration must be configured to 15 minutes or greater.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-002238"
            ]
        },
        {
            "rule": "V-254285",
            "stig_id": "WN22-AC-000010",
            "title": "Windows Server 2022 account lockout duration must be configured to 15 minutes or greater.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-002238"
            ]
        },
        {
            "rule": "V-254286",
            "stig_id": "WN22-AC-000020",
            "title": "Windows Server 2022 must have the number of allowed bad logon attempts configured to three or less.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000044"
            ]
        },
        {
            "rule": "V-254287",
            "stig_id": "WN22-AC-000030",
            "title": "Windows Server 2022 must have the period of time before the bad logon counter is reset configured to 15 minutes or greater.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000044"
            ]
        },
        {
            "rule": "V-230332",
            "stig_id": "RHEL-08-020010",
            "title": "RHEL 8 must automatically lock an account when three unsuccessful logon attempts occur.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000044"
            ]
        },
        {
            "rule": "V-230333",
            "stig_id": "RHEL-08-020011",
            "title": "RHEL 8 must automatically lock an account when three unsuccessful logon attempts occur.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000044"
            ]
        },
        {
            "rule": "V-230334",
            "stig_id": "RHEL-08-020012",
            "title": "RHEL 8 must automatically lock an account when three unsuccessful logon attempts occur during a 15-minute time period.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000044"
            ]
        },
        {
            "rule": "V-230335",
            "stig_id": "RHEL-08-020013",
            "title": "RHEL 8 must automatically lock an account when three unsuccessful logon attempts occur during a 15-minute time period.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000044"
            ]
        },
        {
            "rule": "V-230336",
            "stig_id": "RHEL-08-020014",
            "title": "RHEL 8 must automatically lock an account until the locked account is released by an administrator when three unsuccessful logon attempts occur during a 15-minute time period.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000044"
            ]
        },
        {
            "rule": "V-230337",
            "stig_id": "RHEL-08-020015",
            "title": "RHEL 8 must automatically lock an account until the locked account is released by an administrator when three unsuccessful logon attempts occur during a 15-minute time period.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000044"
            ]
        },
        {
            "rule": "V-230338",
            "stig_id": "RHEL-08-020016",
            "title": "RHEL 8 must ensure account lockouts persist.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000044"
            ]
        },
        {
            "rule": "V-230339",
            "stig_id": "RHEL-08-020017",
            "title": "RHEL 8 must ensure account lockouts persist.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000044"
            ]
        },
        {
            "rule": "V-230340",
            "stig_id": "RHEL-08-020018",
            "title": "RHEL 8 must prevent system messages from being presented when three unsuccessful logon attempts occur.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000044"
            ]
        },
        {
            "rule": "V-230341",
            "stig_id": "RHEL-08-020019",
            "title": "RHEL 8 must prevent system messages from being presented when three unsuccessful logon attempts occur.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000044"
            ]
        },
        {
            "rule": "V-230342",
            "stig_id": "RHEL-08-020020",
            "title": "RHEL 8 must log user name information when unsuccessful logon attempts occur.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000044"
            ]
        },
        {
            "rule": "V-230343",
            "stig_id": "RHEL-08-020021",
            "title": "RHEL 8 must log user name information when unsuccessful logon attempts occur.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000044"
            ]
        },
        {
            "rule": "V-230344",
            "stig_id": "RHEL-08-020022",
            "title": "RHEL 8 must include root when automatically locking an account until the locked account is released by an administrator when three unsuccessful logon attempts occur during a 15-minute time period.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000044"
            ]
        },
        {
            "rule": "V-230345",
            "stig_id": "RHEL-08-020023",
            "title": "RHEL 8 must include root when automatically locking an account until the locked account is released by an administrator when three unsuccessful logon attempts occur during a 15-minute time period.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000044"
            ]
        },
        {
            "rule": "V-244533",
            "stig_id": "RHEL-08-020025",
            "title": "RHEL 8 must configure the use of the pam_faillock.so module in the /etc/pam.d/system-auth file.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000044"
            ]
        },
        {
            "rule": "V-244534",
            "stig_id": "RHEL-08-020026",
            "title": "RHEL 8 must configure the use of the pam_faillock.so module in the /etc/pam.d/password-auth file.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000044"
            ]
        },
        {
            "rule": "V-250315",
            "stig_id": "RHEL-08-020027",
            "title": "RHEL 8 systems, versions 8.2 and above, must configure SELinux context type to allow the use of a non-default faillock tally directory.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000044",
                "CCI-002238"
            ]
        },
        {
            "rule": "V-250316",
            "stig_id": "RHEL-08-020028",
            "title": "RHEL 8 systems below version 8.2 must configure SELinux context type to allow the use of a non-default faillock tally directory.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000044",
                "CCI-002238"
            ]
        },
        {
            "rule": "V-258054",
            "stig_id": "RHEL-09-411075",
            "title": "RHEL 9 must automatically lock an account when three unsuccessful logon attempts occur.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000044",
                "CCI-002238"
            ]
        },
        {
            "rule": "V-258055",
            "stig_id": "RHEL-09-411080",
            "title": "RHEL 9 must automatically lock the root account until the root account is released by an administrator when three unsuccessful logon attempts occur during a 15-minute time period.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000044",
                "CCI-002238"
            ]
        },
        {
            "rule": "V-258056",
            "stig_id": "RHEL-09-411085",
            "title": "RHEL 9 must automatically lock an account when three unsuccessful logon attempts occur during a 15-minute time period.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000044",
                "CCI-002238"
            ]
        },
        {
            "rule": "V-258057",
            "stig_id": "RHEL-09-411090",
            "title": "RHEL 9 must maintain an account lock until the locked account is released by an administrator.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000044",
                "CCI-002238"
            ]
        },
        {
            "rule": "V-258060",
            "stig_id": "RHEL-09-411105",
            "title": "RHEL 9 must ensure account lockouts persist.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000044"
            ]
        },
        {
            "rule": "V-258070",
            "stig_id": "RHEL-09-412045",
            "title": "RHEL 9 must log username information when unsuccessful logon attempts occur.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000044"
            ]
        },
        {
            "rule": "V-258080",
            "stig_id": "RHEL-09-431020",
            "title": "RHEL 9 must configure SELinux context type to allow the use of a nondefault faillock tally directory.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000044"
            ]
        },
        {
            "rule": "V-258095",
            "stig_id": "RHEL-09-611030",
            "title": "RHEL 9 must configure the use of the pam_faillock.so module in the /etc/pam.d/system-auth file.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000044"
            ]
        },
        {
            "rule": "V-258096",
            "stig_id": "RHEL-09-611035",
            "title": "RHEL 9 must configure the use of the pam_faillock.so module in the /etc/pam.d/password-auth file.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000044"
            ]
        }
    ]
}