Automatically lock the account until the locked account is releasedID: oval:org.secpod.oval:def:25081 | Date: (C)2015-06-12 (M)2023-07-04 |
Class: COMPLIANCE | Family: macos |
The operating system must automatically lock the account until the locked account is released by an administrator when three unsuccessful login attempts in 15 minutes are exceeded. By limiting the number of failed login attempts, the risk of unauthorized system access via user password guessing, otherwise known as brute forcing, is reduced. Limits are imposed by locking the account. Setting a lockout expiration of 15 minutes is an effective deterrent against brute forcing that also makes allowances for legitimate mistakes by users.
Platform: |
Apple Mac OS X 10.10 |