AOSX-09-001326 - System must automatically lock the account until it is released by an administrator - 'minutesUntilFailedLoginReset'

Information

By limiting the number of failed login attempts, the risk of unauthorized system access via user password guessing, otherwise known as brute forcing, is reduced. Limits are imposed by locking the account. Setting a lockout expiration of 15 minutes is an effective deterrent against brute forcing that also makes allowances for legitimate mistakes by users.

Solution

To set the password policy, run the following command:

sudo pwpolicy setglobalpolicy 'maxFailedLoginAttempts=3 minutesUntilFailedLoginReset=15'

See Also

http://iasecontent.disa.mil/stigs/zip/U_Apple_OS_X_10-9_Workstation_V1R2_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-7, CAT|II, CCI|CCI-002238, Group-ID|V-58471, Rule-ID|SV-72901r1_rule, STIG-ID|AOSX-09-001326

Plugin: Unix

Control ID: 1aa5e54287cfb092fc2edd2e372836f8532fa02f9b515c83bd2154048123955e