Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-22300 | GEN000454 | SV-25947r1_rule | ECSC-1 | Low |
Description |
---|
Providing users with feedback on recent login failures facilitates user recognition and reporting of attempted unauthorized account use. |
STIG | Date |
---|---|
Draft AIX Security Technical Implementation Guide | 2011-08-17 |
Check Text ( C-30375r1_chk ) |
---|
Determine if the system displays the number of failed login attempts upon logging in. Attempt to log into the system once using an invalid password or other authenticator, then log into the system using the same account with a valid authenticator. If the system does not display a message indicating there was a failed login attempt, this is a finding. |
Fix Text (F-27155r1_fix) |
---|
Configure the system to display the number of failed logins upon logging in. Consult OS documentation for the necessary procedure. |