Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-35133 | SRG-APP-000078-AS-000043 | SV-46420r1_rule | Low |
Description |
---|
Users need to be aware of activity that occurs regarding their application account. Providing users with information regarding the number of unsuccessful attempts made to login to their account allows the user to determine if any unauthorized activity has occurred and gives them an opportunity to notify administrators. This requirement is intended to cover traditional logons to information systems where a user interface is involved. |
STIG | Date |
---|---|
Application Server Security Requirements Guide | 2013-01-08 |
Check Text ( C-43521r1_chk ) |
---|
Review AS product documentation and server configuration to determine if users are informed of the number of unsuccessful login attempts that have occurred during a defined period of time. If the users are not informed of this information this is a finding. |
Fix Text (F-39685r1_fix) |
---|
Configure the AS to display the number of unsuccessful login attempts that have occurred within a defined period of time. |