Skip to main content

πŸ’Ό AC-7 Unsuccessful Logon Attempts (L)(M)(H)

  • Contextual name: πŸ’Ό AC-7 Unsuccessful Logon Attempts (L)(M)(H)
  • ID: /frameworks/fedramp-moderate-security-controls/ac/07
  • Located in: πŸ’Ό Access Control

Description​

a. Enforce a limit of [Assignment: organization-defined number] consecutive invalid logon attempts by a user during a [Assignment: organization-defined time period]; and

b. Automatically [Selection (one-or-more): lock the account or node for an [Assignment: organization-defined time period]; lock the account or node until released by an administrator; delay next logon prompt per [Assignment: organization-defined delay algorithm]; notify system administrator; take other [Assignment: organization-defined action]] when the maximum number of unsuccessful attempts is exceeded.

AC-7 Additional FedRAMP Requirements and Guidance:

Requirement: In alignment with NIST SP 800-63B

Similar​

  • Sections
    • /frameworks/fedramp-high-security-controls/ac/07
  • Internal
    • ID: dec-c-b58f81cf

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό FedRAMP High Security Controls β†’ πŸ’Ό AC-7 Unsuccessful Logon Attempts (L)(M)(H)11

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags

Policies (1)​

PolicyLogic CountFlags
πŸ“ AWS S3 Bucket MFA Delete is not enabled 🟠🟒1🟠 x1, 🟒 x6