Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-55055 | SRG-APP-000065-NDM-000214 | SV-69301r1_rule | Medium |
Description |
---|
By limiting the number of failed login attempts, the risk of unauthorized system access via user password guessing, otherwise known as brute-forcing, is reduced. |
STIG | Date |
---|---|
Network Device Management Security Requirements Guide | 2016-09-30 |
Check Text ( C-55677r1_chk ) |
---|
Determine if the network device is either configured to enforce the limit of three consecutive invalid logon attempts by a user during a 15-minute time period or configured to use an authentication server which would perform this function. If the limit of three consecutive invalid logon attempts by a user during a 15-minute time period is not enforced, this is a finding. |
Fix Text (F-59921r1_fix) |
---|
Configure the network device or its associated authentication server to enforce the limit of three consecutive invalid logon attempts by a user during a 15-minute time period. |