Check: SRG-APP-000065-AU-000240
Central Log Server SRG:
SRG-APP-000065-AU-000240
(in versions v2 r2 through v1 r3)
Title
The Central Log Server must enforce the limit of three consecutive invalid logon attempts by a user during a 15 minute time period. (Cat II impact)
Discussion
By limiting the number of failed login attempts, the risk of unauthorized system access via user password guessing, otherwise known as brute forcing, is reduced. Limits are imposed by locking the account.
Check Content
Examine the configuration. Verify that the Central Log Server is configured to lock out the account after 3 consecutive invalid attempts during a 15 minute period. If the Central Log Server is not configured to lock out the account after 3 consecutive invalid attempts in 15 minutes, this is a finding.
Fix Text
Configure the Central Log Server to lock out the account after 3 consecutive invalid attempts during a 15 minute period.
Additional Identifiers
Rule ID: SV-221904r420056_rule
Vulnerability ID: V-221904
Group Title: SRG-APP-000065
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000044 |
The information system enforces the organization-defined limit of consecutive invalid logon attempts by a user during the organization-defined time period. |
Controls
Number | Title |
---|---|
AC-7 |
Unsuccessful Logon Attempts |