San Antonio, TX · Military City, USA UEI L58JZMKRCLM5  ·  CAGE 203C1  ·  NAICS 541511  ·  SAM.gov Active

AC-7 Unsuccessful Logon Attempts

Access Control family. 16 Control Correlation Identifiers map to this control, and 40 STIG rules implement those CCIs.

0CAT I (high)
40CAT II (medium)
0CAT III (low)
16CCIs
What this page is built from, and what it is not.

The mapping below is derived from 8 DISA STIG benchmarks (Google Chrome Current Windows, Kubernetes, Microsoft Windows 10, Microsoft Windows 11, Microsoft Windows Server 2019, Microsoft Windows Server 2022, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9) covering 2,030 rules, joined to 5,137 Control Correlation Identifiers.

It is not the complete STIG library. A control showing no rules here means no rule in these benchmarks maps to it, not that no STIG covers it. CCI to control mappings are published by DISA and reflect both Revision 4 and Revision 5 of NIST SP 800-53; where the two revisions disagree, both are shown. This page reports what the source data says and nothing further. It is not a compliance determination.

Where these rules come from

STIG benchmarkVersionRules mapped to AC-7
Red Hat Enterprise Linux 8V218
Red Hat Enterprise Linux 9V29
Microsoft Windows 11V24
Microsoft Windows Server 2019V33
Microsoft Windows 10V33
Microsoft Windows Server 2022V23

Control Correlation Identifiers mapped to AC-7

CCIDefinitionRev
CCI-000043Defines the maximum number of consecutive invalid logon attempts to the information system by a user during an organization-defined time period.5, 4
CCI-000044Enforce the organization-defined limit of consecutive invalid logon attempts by a user during the organization-defined time period.5, 4
CCI-001423Defines the time period in which the organization-defined maximum number of consecutive invalid logon attempts occur.5, 4
CCI-002236Defines the time period the information system will automatically lock the account or node when the maximum number of unsuccessful logon attempts is exceeded.5, 4
CCI-002237Defines the delay algorithm to delay the next logon prompt when the maximum number of unsuccessful logon attempts is exceeded.5, 4
CCI-002238Automatically lock the account or node for either an organization-defined time period, until the locked account or node is released by an administrator, or delays the next logon prompt according to the organization-defined delay algorithm when the maximum number of unsuccessful logon attempts is exceeded.5, 4
CCI-002239Defines the mobile devices that are to be purged or wiped after an organization-defined number of consecutive, unsuccessful device logon attempts.5, 4
CCI-002240Defines the purging or wiping requirements and techniques to be used on organization-defined mobile devices after an organization-defined number of consecutive, unsuccessful device logon attempts.5, 4
CCI-002241Defines the number of consecutive, unsuccessful device logon attempts after which the organization-defined mobile devices will be purged or wiped.5, 4
CCI-002242Purge or wipe information from organization-defined mobile devices based on organization-defined purging or wiping requirements and techniques after an organization-defined number of consecutive, unsuccessful device logon attempts.5, 4
CCI-003687Limit the number of unsuccessful biometric logon attempts to an organization-defined number.5
CCI-003688Defines the number of allowed unsuccessful biometric logon attempts.5
CCI-003689Allow the use of organization-defined authentication factors that are different from the primary authentication factors after the number of organization-defined consecutive invalid logon attempts have been exceeded.5
CCI-003690Defines the authentication factors after a number of organization-defined consecutive invalid logon attempts have been executed.5
CCI-003691Enforce a limit of organization-defined number consecutive invalid logon attempts through use of the alternative factors by a user during a organization-defined time period.5
CCI-003692Defines the number enforced for logon attempts.5

STIG rules that implement AC-7

RuleSTIG IDSeverityRequirement
V-205629WN19-AC-000020mediumWindows Server 2019 must have the number of allowed bad logon attempts configured to three or less.
V-205630WN19-AC-000030mediumWindows Server 2019 must have the period of time before the bad logon counter is reset configured to 15 minutes or greater.
V-205795WN19-AC-000010mediumWindows Server 2019 account lockout duration must be configured to 15 minutes or greater.
V-220739WN10-AC-000005mediumWindows 10 account lockout duration must be configured to 15 minutes or greater.
V-220740WN10-AC-000010mediumThe number of allowed bad logon attempts must be configured to 3 or less.
V-220741WN10-AC-000015mediumThe period of time before the bad logon counter is reset must be configured to 15 minutes.
V-230332RHEL-08-020010mediumRHEL 8 must automatically lock an account when three unsuccessful logon attempts occur.
V-230333RHEL-08-020011mediumRHEL 8 must automatically lock an account when three unsuccessful logon attempts occur.
V-230334RHEL-08-020012mediumRHEL 8 must automatically lock an account when three unsuccessful logon attempts occur during a 15-minute time period.
V-230335RHEL-08-020013mediumRHEL 8 must automatically lock an account when three unsuccessful logon attempts occur during a 15-minute time period.
V-230336RHEL-08-020014mediumRHEL 8 must automatically lock an account until the locked account is released by an administrator when three unsuccessful logon attempts occur during a 15-minute time period.
V-230337RHEL-08-020015mediumRHEL 8 must automatically lock an account until the locked account is released by an administrator when three unsuccessful logon attempts occur during a 15-minute time period.
V-230338RHEL-08-020016mediumRHEL 8 must ensure account lockouts persist.
V-230339RHEL-08-020017mediumRHEL 8 must ensure account lockouts persist.
V-230340RHEL-08-020018mediumRHEL 8 must prevent system messages from being presented when three unsuccessful logon attempts occur.
V-230341RHEL-08-020019mediumRHEL 8 must prevent system messages from being presented when three unsuccessful logon attempts occur.
V-230342RHEL-08-020020mediumRHEL 8 must log user name information when unsuccessful logon attempts occur.
V-230343RHEL-08-020021mediumRHEL 8 must log user name information when unsuccessful logon attempts occur.
V-230344RHEL-08-020022mediumRHEL 8 must include root when automatically locking an account until the locked account is released by an administrator when three unsuccessful logon attempts occur during a 15-minute time period.
V-230345RHEL-08-020023mediumRHEL 8 must include root when automatically locking an account until the locked account is released by an administrator when three unsuccessful logon attempts occur during a 15-minute time period.
V-244533RHEL-08-020025mediumRHEL 8 must configure the use of the pam_faillock.so module in the /etc/pam.d/system-auth file.
V-244534RHEL-08-020026mediumRHEL 8 must configure the use of the pam_faillock.so module in the /etc/pam.d/password-auth file.
V-250315RHEL-08-020027mediumRHEL 8 systems, versions 8.2 and above, must configure SELinux context type to allow the use of a non-default faillock tally directory.
V-250316RHEL-08-020028mediumRHEL 8 systems below version 8.2 must configure SELinux context type to allow the use of a non-default faillock tally directory.
V-253297WN11-AC-000005mediumWindows 11 account lockout duration must be configured to 15 minutes or greater.
V-253298WN11-AC-000010mediumThe number of allowed bad logon attempts must be configured to three or less.
V-253299WN11-AC-000015mediumThe period of time before the bad logon counter is reset must be configured to 15 minutes.
V-253445WN11-SO-000075mediumThe required legal notice must be configured to display before console logon.
V-254285WN22-AC-000010mediumWindows Server 2022 account lockout duration must be configured to 15 minutes or greater.
V-254286WN22-AC-000020mediumWindows Server 2022 must have the number of allowed bad logon attempts configured to three or less.
V-254287WN22-AC-000030mediumWindows Server 2022 must have the period of time before the bad logon counter is reset configured to 15 minutes or greater.
V-258054RHEL-09-411075mediumRHEL 9 must automatically lock an account when three unsuccessful logon attempts occur.
V-258055RHEL-09-411080mediumRHEL 9 must automatically lock the root account until the root account is released by an administrator when three unsuccessful logon attempts occur during a 15-minute time period.
V-258056RHEL-09-411085mediumRHEL 9 must automatically lock an account when three unsuccessful logon attempts occur during a 15-minute time period.
V-258057RHEL-09-411090mediumRHEL 9 must maintain an account lock until the locked account is released by an administrator.
V-258060RHEL-09-411105mediumRHEL 9 must ensure account lockouts persist.
V-258070RHEL-09-412045mediumRHEL 9 must log username information when unsuccessful logon attempts occur.
V-258080RHEL-09-431020mediumRHEL 9 must configure SELinux context type to allow the use of a nondefault faillock tally directory.
V-258095RHEL-09-611030mediumRHEL 9 must configure the use of the pam_faillock.so module in the /etc/pam.d/system-auth file.
V-258096RHEL-09-611035mediumRHEL 9 must configure the use of the pam_faillock.so module in the /etc/pam.d/password-auth file.

Get this as data

The same mapping is served as JSON, no key required: /api/v1/stig-nist/control/AC-7. The interactive version of the full cube is the STIG to NIST mapper, and the endpoint is documented on the compliance API page.