Check: 4.003
Win2k3 Audit:
4.003
(in version v6 r1.29)
Title
Time before bad-logon counter is reset does not meet minimum requirements. (Cat II impact)
Discussion
This parameter specifies the amount of time that must pass between two successive login attempts to ensure that a lockout will occur. The smaller this value is, the less effective the account lockout feature will be in protecting the local system.
Check Content
Fix Text
Configure the system to have the lockout counter reset itself after a minimum of 60 minutes.
Additional Identifiers
Rule ID: SV-29637r1_rule
Vulnerability ID: V-1098
Group Title:
Expert Comments
Expert comments are only available to logged-in users.
CCIs
CCIs tied to check.
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Controls tied to check. These are derived from the CCIs shown above.
Number | Title |
---|---|
No controls are assigned to this check |