UCF STIG Viewer Logo

The system must display the number of unsuccessful login attempts since the last successful login for a user account upon logging in.


Overview

Finding ID Version Rule ID IA Controls Severity
V-22300 GEN000454 SV-25947r1_rule ECSC-1 Low
Description
Providing users with feedback on recent login failures facilitates user recognition and reporting of attempted unauthorized account use.
STIG Date
Draft AIX Security Technical Implementation Guide 2011-08-17

Details

Check Text ( C-30375r1_chk )
Determine if the system displays the number of failed login attempts upon logging in. Attempt to log into the system once using an invalid password or other authenticator, then log into the system using the same account with a valid authenticator. If the system does not display a message indicating there was a failed login attempt, this is a finding.
Fix Text (F-27155r1_fix)
Configure the system to display the number of failed logins upon logging in. Consult OS documentation for the necessary procedure.