CCI-002237
CCI-002237 Definition
| Status | |
| Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
Determine if automatically [AC-07_ODP[03]; one or more of the following PARAMETER VALUES is/are selected: {lock the account or node for [AC-07_ODP[04]; time period for an account or node to be locked is defined (if selected);]; lock the account or node until released by an administrator; delay next logon prompt per [AC-07_ODP[05]; delay algorithm for the next logon prompt is defined (if selected)]; notify system administrator; take other [AC-07_ODP[06]; other action to be taken when the maximum number of unsuccessful attempts is exceeded is defined (if selected)]]]] when the maximum number of unsuccessful attempts is exceeded.
Validation Procedures
Examine: [SELECT FROM: Access control policy; procedures addressing unsuccessful logon attempts; system design documentation; system configuration settings and associated documentation; system audit records; system security plan; other relevant documents or records]. Interview: [SELECT FROM: Organizational personnel with information security responsibilities; system developers; system/network administrators]. Test: [SELECT FROM: Mechanisms implementing access control policy for unsuccessful logon attempts].