5.2.1 Configure account lockout threshold

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

The account lockout threshold specifies the amount of times a user can enter an incorrect password before a lockout will occur.

Ensure that a lockout threshold is part of the password policy on the computer

Rationale:

The account lockout feature mitigates brute-force password attacks on the system.

Solution

Perform the following to implement the prescribed state for all pwpolicy controls

1. Run the following command in Terminal:

pwpolicy -setaccountpolicies

Examples in pwpolicy man page

See Also

https://workbench.cisecurity.org/files/2105

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-7, CSCv6|16.7

Plugin: Unix

Control ID: 2d6d7a4b5ea1a6037001d9c238cb47e63245c3b218fccc4deabdf46a8cab7b0d