CCE-2986-8Platform: winxp | Date: (C)2012-03-13 (M)2017-07-28 |
The "account lockout threshold" policy should meet minimum requirements.
Parameter:
(1) number of attempts
Technical Mechanism:
(1) defined by Local or Group Policy
References:
Resource Id | Reference |
---|
Old v4 CCE ID | CCE-658 |
DISA Gold Disk for Windows XP | Lockout Count (CID:43) |
NSA Security Guide for Windows XP (NSA-XP-C44-026-02.pdf) | Account lockout threshold (3 invalid attempts) |
CIS Windows XP Pro Benchmark v1.3 | 2.2.3.2 Account Lockout Threshold |
NIST 800-68 Windows XP PDF (SP800-68-20051102.pdf) | Account lockout threshold Table: 2.2 Value: 10, 50 |
NIST 800-68 Windows XP XCCDF (NIST-800-68-53-WinXPPro_XCCDF_10102006.xml) | AccountLockoutThreshold |
NIST 800-68 Windows XP OVAL (NIST-800-68-53-WinXPPro_OVAL_10102006.xml) | oval:gov.nist.1:def:24 |
FDCC Windows XP XCCDF (fdcc-accepted-content-20080110\fdcc-winxp-xccdf.xml) | account_lockout_threshold |
FDCC Windows XP OVAL (fdcc-accepted-content-20080110\fdcc-winxp-oval.xml) | oval:gov.nist.fdcc.xp:def:24 |
SCAP Repo OVAL Definition | oval:gov.nist.usgcb.xp:def:24 |
BITS Shared Assessments SIG v6.0 | BITS Shared Assessments SIG v6.0 |
Jericho Forum | Jericho Forum |
HIPAA/HITECH Act | HIPAA/HITECH Act |
FedRAMP Security Controls(Final Release Jan 2012)--LOW IMPACT LEVEL-- | FedRAMP Security Controls(Final Release Jan 2012)--LOW IMPACT LEVEL-- |
ISO/IEC 27001-2005 | ISO/IEC 27001-2005 |
COBIT 4.1 | COBIT 4.1 |
GAPP (Aug 2009) | GAPP (Aug 2009) |
NERC CIP | NERC CIP |
NIST SP800-53 R3 | NIST SP800-53 R3 AC-7 |
NIST SP800-53 R3 | NIST SP800-53 R3 CM-6 |
PCIDSS v2.0 | PCIDSS v2.0 |
FedRAMP Security Controls(Final Release Jan 2012)--MODERATE IMPACT LEVEL-- | FedRAMP Security Controls(Final Release Jan 2012)--MODERATE IMPACT LEVEL-- |
BITS Shared Assessments AUP v5.0 | BITS Shared Assessments AUP v5.0 |