UCF STIG Viewer Logo

The administrator/MDM must set the maximum number of consecutive failed authentication attempts for the device unlock password to 10 or less.


Overview

Finding ID Version Rule ID IA Controls Severity
V-48317 KNOX-24-008900 SV-61189r1_rule Low
Description
Users must not be able to override the system policy on the maximum number of consecutive failed authentication attempts because this could allow them to raise the maximum, thus giving adversaries more chances to guess/brute force passwords, which increases the risk of the mobile device being compromised. Therefore, only administrators and the MDM software should have the authority to set consecutive failed authentication attempt policies. SFR ID: FMT_SMF.1.1 #02
STIG Date
Samsung Android (with Knox 1.x) STIG 2014-04-22

Details

Check Text ( C-50749r1_chk )
This validation procedure is performed on both the MDM Administration Console and the Samsung Knox Android device.

Check whether the appropriate setting is configured on the MDM Administration Console:
1. Ask the MDM administrator to display the "Maximum Failed Attempts" field in the "Android Password Restrictions" rule for the device unlock password.
2. Verify the value of the setting is 10 or less.

This configuration is not available on the Samsung Knox Android device.
Fix Text (F-51925r1_fix)
Configure the mobile device to allow only 10 or less consecutive failed authentication attempts.

On the MDM Administration Console, set the "Maximum Failed Attempts" to 10 or less in the "Android Password Restrictions" rule for the device unlock password.