1. Home
  2. Security Hardening
  3. DISA STIG Apple Mac OSX 10 15 V1R7
  4. AOSX-15-000021 – The macOS system must enforce an account lockout time period of 15 minutes in which a user makes three consecutive invalid logon attempts.

AOSX-15-000021 – The macOS system must enforce an account lockout time period of 15 minutes in which a user makes three consecutive invalid logon attempts.

Details

Setting a lockout time period of 15 minutes is an effective deterrent against brute forcing that also makes allowances for legitimate mistakes by users. When three invalid logon attempts are made, the account will be locked.

Solution

This setting is enforced using the ‘Passcode Policy’ configuration profile or by a directory service.

Supportive Information

The following resource is also helpful.

This security hardening control applies to the following category of controls within NIST 800-53: Access Control.This control applies to the following type of system Unix.

References

Source

Updated on July 16, 2022
Was this article helpful?

Related Articles