5.2.1 Configure account lockout threshold

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

The account lockout feature mitigates brute-force password attacks on the system.

Solution

Perform the following to implement the prescribed state for all pwpolicy controls
1. Run the following command in Terminal:
pwpolicy -setaccountpolicies
Examples in pwpolicy man page and in the back of the Benchmark

See Also

https://benchmarks.cisecurity.org/tools2/osx/CIS_Apple_OSX_10.11_Benchmark_v1.0.0.pdf

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-7, CSCv6|16.7

Plugin: Unix

Control ID: 1157634a9d696a0990f98b925f62752ff42c42023d9c393a61474773d115ae97