DG0133: DBMS Account lock time - 'Account Lockout Duration = 0'

Information

ref: DISA DB STIG SQL 2005 V8
ref: Vulnerability Key: V0015639
ref: STIG ID: DG0133-SQLServer9
ref: Severity: Category II
Unlimited account lock times should be specified for locked accounts.
When no limit is imposed on failed logon attempts and accounts are not disabled after a set number of failed access attempts, then the
DBMS account is vulnerable to sustained attack. When access attempts may continue unrestricted, the likelihood of success is increased. A
successful attempt results in unauthorized access to the database.
ref: U_INS_sqlserver9_v8r1.7_Checklist_20100827.pdf pg. 115