AC-7 Unsuccessful Logon Attempts
Access Control family. 16 Control Correlation Identifiers map to this control, and 40 STIG rules implement those CCIs.
The mapping below is derived from 8 DISA STIG benchmarks (Google Chrome Current Windows, Kubernetes, Microsoft Windows 10, Microsoft Windows 11, Microsoft Windows Server 2019, Microsoft Windows Server 2022, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9) covering 2,030 rules, joined to 5,137 Control Correlation Identifiers.
It is not the complete STIG library. A control showing no rules here means no rule in these benchmarks maps to it, not that no STIG covers it. CCI to control mappings are published by DISA and reflect both Revision 4 and Revision 5 of NIST SP 800-53; where the two revisions disagree, both are shown. This page reports what the source data says and nothing further. It is not a compliance determination.
Where these rules come from
| STIG benchmark | Version | Rules mapped to AC-7 |
|---|---|---|
| Red Hat Enterprise Linux 8 | V2 | 18 |
| Red Hat Enterprise Linux 9 | V2 | 9 |
| Microsoft Windows 11 | V2 | 4 |
| Microsoft Windows Server 2019 | V3 | 3 |
| Microsoft Windows 10 | V3 | 3 |
| Microsoft Windows Server 2022 | V2 | 3 |
Control Correlation Identifiers mapped to AC-7
| CCI | Definition | Rev |
|---|---|---|
| CCI-000043 | Defines the maximum number of consecutive invalid logon attempts to the information system by a user during an organization-defined time period. | 5, 4 |
| CCI-000044 | Enforce the organization-defined limit of consecutive invalid logon attempts by a user during the organization-defined time period. | 5, 4 |
| CCI-001423 | Defines the time period in which the organization-defined maximum number of consecutive invalid logon attempts occur. | 5, 4 |
| CCI-002236 | Defines the time period the information system will automatically lock the account or node when the maximum number of unsuccessful logon attempts is exceeded. | 5, 4 |
| CCI-002237 | Defines the delay algorithm to delay the next logon prompt when the maximum number of unsuccessful logon attempts is exceeded. | 5, 4 |
| CCI-002238 | Automatically lock the account or node for either an organization-defined time period, until the locked account or node is released by an administrator, or delays the next logon prompt according to the organization-defined delay algorithm when the maximum number of unsuccessful logon attempts is exceeded. | 5, 4 |
| CCI-002239 | Defines the mobile devices that are to be purged or wiped after an organization-defined number of consecutive, unsuccessful device logon attempts. | 5, 4 |
| CCI-002240 | Defines the purging or wiping requirements and techniques to be used on organization-defined mobile devices after an organization-defined number of consecutive, unsuccessful device logon attempts. | 5, 4 |
| CCI-002241 | Defines the number of consecutive, unsuccessful device logon attempts after which the organization-defined mobile devices will be purged or wiped. | 5, 4 |
| CCI-002242 | Purge or wipe information from organization-defined mobile devices based on organization-defined purging or wiping requirements and techniques after an organization-defined number of consecutive, unsuccessful device logon attempts. | 5, 4 |
| CCI-003687 | Limit the number of unsuccessful biometric logon attempts to an organization-defined number. | 5 |
| CCI-003688 | Defines the number of allowed unsuccessful biometric logon attempts. | 5 |
| CCI-003689 | Allow the use of organization-defined authentication factors that are different from the primary authentication factors after the number of organization-defined consecutive invalid logon attempts have been exceeded. | 5 |
| CCI-003690 | Defines the authentication factors after a number of organization-defined consecutive invalid logon attempts have been executed. | 5 |
| CCI-003691 | Enforce a limit of organization-defined number consecutive invalid logon attempts through use of the alternative factors by a user during a organization-defined time period. | 5 |
| CCI-003692 | Defines the number enforced for logon attempts. | 5 |
STIG rules that implement AC-7
| Rule | STIG ID | Severity | Requirement |
|---|---|---|---|
| V-205629 | WN19-AC-000020 | medium | Windows Server 2019 must have the number of allowed bad logon attempts configured to three or less. |
| V-205630 | WN19-AC-000030 | medium | Windows Server 2019 must have the period of time before the bad logon counter is reset configured to 15 minutes or greater. |
| V-205795 | WN19-AC-000010 | medium | Windows Server 2019 account lockout duration must be configured to 15 minutes or greater. |
| V-220739 | WN10-AC-000005 | medium | Windows 10 account lockout duration must be configured to 15 minutes or greater. |
| V-220740 | WN10-AC-000010 | medium | The number of allowed bad logon attempts must be configured to 3 or less. |
| V-220741 | WN10-AC-000015 | medium | The period of time before the bad logon counter is reset must be configured to 15 minutes. |
| V-230332 | RHEL-08-020010 | medium | RHEL 8 must automatically lock an account when three unsuccessful logon attempts occur. |
| V-230333 | RHEL-08-020011 | medium | RHEL 8 must automatically lock an account when three unsuccessful logon attempts occur. |
| V-230334 | RHEL-08-020012 | medium | RHEL 8 must automatically lock an account when three unsuccessful logon attempts occur during a 15-minute time period. |
| V-230335 | RHEL-08-020013 | medium | RHEL 8 must automatically lock an account when three unsuccessful logon attempts occur during a 15-minute time period. |
| V-230336 | RHEL-08-020014 | medium | RHEL 8 must automatically lock an account until the locked account is released by an administrator when three unsuccessful logon attempts occur during a 15-minute time period. |
| V-230337 | RHEL-08-020015 | medium | RHEL 8 must automatically lock an account until the locked account is released by an administrator when three unsuccessful logon attempts occur during a 15-minute time period. |
| V-230338 | RHEL-08-020016 | medium | RHEL 8 must ensure account lockouts persist. |
| V-230339 | RHEL-08-020017 | medium | RHEL 8 must ensure account lockouts persist. |
| V-230340 | RHEL-08-020018 | medium | RHEL 8 must prevent system messages from being presented when three unsuccessful logon attempts occur. |
| V-230341 | RHEL-08-020019 | medium | RHEL 8 must prevent system messages from being presented when three unsuccessful logon attempts occur. |
| V-230342 | RHEL-08-020020 | medium | RHEL 8 must log user name information when unsuccessful logon attempts occur. |
| V-230343 | RHEL-08-020021 | medium | RHEL 8 must log user name information when unsuccessful logon attempts occur. |
| V-230344 | RHEL-08-020022 | medium | RHEL 8 must include root when automatically locking an account until the locked account is released by an administrator when three unsuccessful logon attempts occur during a 15-minute time period. |
| V-230345 | RHEL-08-020023 | medium | RHEL 8 must include root when automatically locking an account until the locked account is released by an administrator when three unsuccessful logon attempts occur during a 15-minute time period. |
| V-244533 | RHEL-08-020025 | medium | RHEL 8 must configure the use of the pam_faillock.so module in the /etc/pam.d/system-auth file. |
| V-244534 | RHEL-08-020026 | medium | RHEL 8 must configure the use of the pam_faillock.so module in the /etc/pam.d/password-auth file. |
| V-250315 | RHEL-08-020027 | medium | RHEL 8 systems, versions 8.2 and above, must configure SELinux context type to allow the use of a non-default faillock tally directory. |
| V-250316 | RHEL-08-020028 | medium | RHEL 8 systems below version 8.2 must configure SELinux context type to allow the use of a non-default faillock tally directory. |
| V-253297 | WN11-AC-000005 | medium | Windows 11 account lockout duration must be configured to 15 minutes or greater. |
| V-253298 | WN11-AC-000010 | medium | The number of allowed bad logon attempts must be configured to three or less. |
| V-253299 | WN11-AC-000015 | medium | The period of time before the bad logon counter is reset must be configured to 15 minutes. |
| V-253445 | WN11-SO-000075 | medium | The required legal notice must be configured to display before console logon. |
| V-254285 | WN22-AC-000010 | medium | Windows Server 2022 account lockout duration must be configured to 15 minutes or greater. |
| V-254286 | WN22-AC-000020 | medium | Windows Server 2022 must have the number of allowed bad logon attempts configured to three or less. |
| V-254287 | WN22-AC-000030 | medium | Windows Server 2022 must have the period of time before the bad logon counter is reset configured to 15 minutes or greater. |
| V-258054 | RHEL-09-411075 | medium | RHEL 9 must automatically lock an account when three unsuccessful logon attempts occur. |
| V-258055 | RHEL-09-411080 | medium | RHEL 9 must automatically lock the root account until the root account is released by an administrator when three unsuccessful logon attempts occur during a 15-minute time period. |
| V-258056 | RHEL-09-411085 | medium | RHEL 9 must automatically lock an account when three unsuccessful logon attempts occur during a 15-minute time period. |
| V-258057 | RHEL-09-411090 | medium | RHEL 9 must maintain an account lock until the locked account is released by an administrator. |
| V-258060 | RHEL-09-411105 | medium | RHEL 9 must ensure account lockouts persist. |
| V-258070 | RHEL-09-412045 | medium | RHEL 9 must log username information when unsuccessful logon attempts occur. |
| V-258080 | RHEL-09-431020 | medium | RHEL 9 must configure SELinux context type to allow the use of a nondefault faillock tally directory. |
| V-258095 | RHEL-09-611030 | medium | RHEL 9 must configure the use of the pam_faillock.so module in the /etc/pam.d/system-auth file. |
| V-258096 | RHEL-09-611035 | medium | RHEL 9 must configure the use of the pam_faillock.so module in the /etc/pam.d/password-auth file. |
Get this as data
The same mapping is served as JSON, no key required: /api/v1/stig-nist/control/AC-7. The interactive version of the full cube is the STIG to NIST mapper, and the endpoint is documented on the compliance API page.