10.5 Lock Inactive User Accounts

Information

User accounts that have been inactive for over a given period of time can be automatically disabled. It is recommended that accounts that are inactive for 35 or more days be disabled. Inactive accounts pose a threat to system security since the users are not logging in to notice failed login attempts or other anomalies.

Solution

# useradd -D -f 35

See Also

https://workbench.cisecurity.org/files/85

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-2(3), CSCv6|16.1, CSCv6|16.6

Plugin: Unix

Control ID: 3a691a69f9c79cb43cc678e96ad1a9949f8c57ca98812af441b54c08e8d583a5