Skip to main content

πŸ’Ό 8.3.4 Invalid authentication attempts are limited.

Description​

Limited by:

  • Locking out the user ID after not more than 10 attempts.
  • Setting the lockout duration to a minimum of 30 minutes or until the user's identity is confirmed.

Similar​

  • Sections
    • /frameworks/pci-dss-v3.2.1/08/01/06
    • /frameworks/pci-dss-v3.2.1/08/01/07
    • /frameworks/pci-dss-v4.0.1/08/03/04

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό PCI DSS v3.2.1 β†’ πŸ’Ό 8.1.6 Limit repeated access attempts by locking out the user ID after not more than six attempts.
πŸ’Ό PCI DSS v3.2.1 β†’ πŸ’Ό 8.1.7 Set the lockout duration to a minimum of 30 minutes or until an administrator enables the user ID.
πŸ’Ό PCI DSS v4.0.1 β†’ πŸ’Ό 8.3.4 Invalid authentication attempts are limited.

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό PCI DSS v3.2.1 β†’ πŸ’Ό 8.1.6 Limit repeated access attempts by locking out the user ID after not more than six attempts.
πŸ’Ό PCI DSS v3.2.1 β†’ πŸ’Ό 8.1.7 Set the lockout duration to a minimum of 30 minutes or until an administrator enables the user ID.
πŸ’Ό PCI DSS v4.0.1 β†’ πŸ’Ό 8.3.4 Invalid authentication attempts are limited.

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags