| 1.8 APPL-15-000022 | CIS Apple macOS 15 Sequoia STIG v1.0.0 CAT II | Unix | ACCESS CONTROL |
| 1.9 APPL-26-000022 | CIS Apple macOS 26 Tahoe STIG v1.0.0 CAT II | Unix | ACCESS CONTROL |
| 1.21 APPL-15-000060 | CIS Apple macOS 15 Sequoia STIG v1.0.0 CAT II | Unix | ACCESS CONTROL |
| 1.21 APPL-26-000060 | CIS Apple macOS 26 Tahoe STIG v1.0.0 CAT II | Unix | ACCESS CONTROL |
| 1.21 VCSA-80-000145 | CIS VMware vSphere 8.0 vCenter STIG v1.0.0 CAT II | VMware | ACCESS CONTROL |
| 1.47 WN10-AC-000015 | CIS Microsoft Windows 10 STIG v1.0.0 CAT II | Windows | ACCESS CONTROL |
| 1.50 WN19-AC-000030 | CIS Microsoft Windows Server 2019 STIG v4.0.0 DC CAT II | Windows | ACCESS CONTROL |
| 1.50 WN19-AC-000030 | CIS Microsoft Windows Server 2019 STIG v4.0.0 MS CAT II | Windows | ACCESS CONTROL |
| 1.151 OL08-00-020025 | CIS Oracle Linux 8 STIG v1.0.0 CAT II | Unix | ACCESS CONTROL |
| 1.153 OL08-00-020027 | CIS Oracle Linux 8 STIG v1.0.0 CAT II | Unix | ACCESS CONTROL |
| 1.162 AZLX-23-002460 | CIS Amazon Linux 2023 STIG v1.0.0 CAT II | Unix | ACCESS CONTROL |
| 1.264 RHEL-10-600415 | CIS Red Hat Enterprise Linux 10 STIG v1.0.0 CAT II | Unix | ACCESS CONTROL |
| 1.267 RHEL-10-600430 | CIS Red Hat Enterprise Linux 10 STIG v1.0.0 CAT II | Unix | ACCESS CONTROL |
| 1.279 RHEL-09-411075 | CIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II | Unix | ACCESS CONTROL |
| 1.281 RHEL-09-411085 | CIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II | Unix | ACCESS CONTROL |
| 1.317 OL09-00-002416 | CIS Oracle Linux 9 STIG v1.0.0 CAT II | Unix | ACCESS CONTROL |
| 1.318 OL09-00-002417 | CIS Oracle Linux 9 STIG v1.0.0 CAT II | Unix | ACCESS CONTROL |
| 1.400 OL09-00-003020 | CIS Oracle Linux 9 STIG v1.0.0 CAT II | Unix | ACCESS CONTROL |
| 1.401 OL09-00-003021 | CIS Oracle Linux 9 STIG v1.0.0 CAT II | Unix | ACCESS CONTROL |
| 4.003 - Time before bad-logon counter is reset does not meet minimum requirements. | DISA Windows Vista STIG v6r41 | Windows | ACCESS CONTROL |
| 5.4.13 Ensure lockout for unsuccessful root logon attempts | CIS Amazon Linux 2 STIG v2.0.1 STIG | Unix | ACCESS CONTROL |
| APPL-11-000022 - The macOS system must enforce the limit of three consecutive invalid logon attempts by a user before the user account is locked - maxFailedAttempts | DISA STIG Apple macOS 11 v1r8 | Unix | ACCESS CONTROL |
| APPL-11-000022 - The macOS system must enforce the limit of three consecutive invalid logon attempts by a user before the user account is locked - minutesUntilFailedLoginReset | DISA STIG Apple macOS 11 v1r5 | Unix | ACCESS CONTROL |
| APPL-11-000022 - The macOS system must enforce the limit of three consecutive invalid logon attempts by a user before the user account is locked - minutesUntilFailedLoginReset | DISA STIG Apple macOS 11 v1r8 | Unix | ACCESS CONTROL |
| APPL-13-000022 - The macOS system must enforce the limit of three consecutive invalid logon attempts by a user before the user account is locked. | DISA STIG Apple macOS 13 v1r5 | Unix | ACCESS CONTROL |
| APPL-15-000060 - The macOS system must set account lockout time to 15 minutes. | DISA Apple macOS 15 Sequoia STIG v1r7 | Unix | ACCESS CONTROL |
| ESXI-70-000006 - The ESXi host must enforce an unlock timeout of 15 minutes after a user account is locked out. | DISA VMware vSphere 7.0 ESXi STIG v1r4 VMware | VMware | ACCESS CONTROL |
| GEN000480 - The delay between login prompts following a failed login attempt must be at least 4 seconds - '/etc/pam.d/system-auth-local' | DISA STIG for Red Hat Enterprise Linux 5 v1r18 Audit | Unix | ACCESS CONTROL |
| GEN000480 - The delay between login prompts following a failed login attempt must be at least 4 seconds - '/etc/pam.d/system-auth-local' | DISA STIG for Oracle Linux 5 v2r1 | Unix | ACCESS CONTROL |
| GEN000480 - The delay between login prompts following a failed login attempt must be at least 4 seconds. | DISA STIG AIX 6.1 v1r14 | Unix | ACCESS CONTROL |
| GEN000480 - The delay between login prompts following a failed login attempt must be at least 4 seconds. | DISA STIG for Red Hat Enterprise Linux 5 v1r18 Audit | Unix | ACCESS CONTROL |
| GEN000480 - The delay between login prompts following a failed login attempt must be at least 4 seconds. | DISA STIG Solaris 10 SPARC v2r4 | Unix | ACCESS CONTROL |
| GEN000480 - The delay between login prompts following a failed login attempt must be at least 4 seconds. | DISA STIG for Oracle Linux 5 v2r1 | Unix | ACCESS CONTROL |
| GEN000480 - The delay between login prompts following a failed login attempt must be at least 4 seconds. | DISA STIG Solaris 10 X86 v2r4 | Unix | ACCESS CONTROL |
| OL08-00-020013 - OL 8 systems, versions 8.2 and above, must automatically lock an account when three unsuccessful logon attempts occur during a 15-minute time period. | DISA Oracle Linux 8 STIG v2r8 | Unix | ACCESS CONTROL |
| OL08-00-020017 - OL 8 systems, versions 8.2 and above, must ensure account lockouts persist. | DISA Oracle Linux 8 STIG v2r8 | Unix | ACCESS CONTROL |
| OL08-00-020025 - OL 8 must configure the use of the pam_faillock.so module in the /etc/pam.d/system-auth file. | DISA Oracle Linux 8 STIG v2r8 | Unix | ACCESS CONTROL |
| RHEL-10-600200 - RHEL 10 must enforce a delay of at least four seconds between login prompts following a failed login attempt. | DISA Red Hat Enterprise Linux 10 STIG v1r1 | Unix | ACCESS CONTROL |
| RHEL-10-600410 - RHEL 10 must automatically lock an account when three unsuccessful login attempts occur. | DISA Red Hat Enterprise Linux 10 STIG v1r1 | Unix | ACCESS CONTROL |
| SLES-15-020010 - The SUSE operating system must lock an account after three consecutive invalid access attempts. | DISA SUSE Linux Enterprise Server 15 STIG v2r6 | Unix | ACCESS CONTROL |
| SPLK-CL-000070 - Splunk Enterprise must automatically lock the account until the locked account is released by an administrator when three unsuccessful login attempts in 15 minutes are exceeded. | DISA STIG Splunk Enterprise 8.x for Linux v2r3 STIG OS | Unix | ACCESS CONTROL |
| UBTU-22-411045 - Ubuntu 22.04 LTS must automatically lock an account until the locked account is released by an administrator when three unsuccessful logon attempts have been made. | DISA Canonical Ubuntu 22.04 LTS STIG v2r8 | Unix | ACCESS CONTROL |
| VCSA-70-000145 - The vCenter Server must set the interval for counting failed login attempts to at least 15 minutes. | DISA STIG VMware vSphere 7.0 vCenter v1r3 | VMware | ACCESS CONTROL |
| VCSA-70-000266 - The vCenter Server must require an administrator to unlock an account locked due to excessive login failures. | DISA STIG VMware vSphere 7.0 vCenter v1r3 | VMware | ACCESS CONTROL |
| VCSA-80-000145 - The vCenter Server must set the interval for counting failed login attempts to at least 15 minutes. | DISA VMware vSphere 8.0 vCenter STIG v2r3 | VMware | ACCESS CONTROL |
| VCTR-67-000047 - The vCenter Server must require an administrator to unlock an account locked due to excessive login failures. | DISA STIG VMware vSphere 6.7 vCenter v1r4 | VMware | ACCESS CONTROL |
| VCWN-06-000045 - The system must limit the maximum number of failed login attempts to three. | DISA VMware vSphere vCenter Server Version 6 STIG v1r4 | VMware | ACCESS CONTROL |
| VCWN-06-000046 - The system must set the interval for counting failed login attempts to at least 15 minutes. | DISA VMware vSphere vCenter Server Version 6 STIG v1r4 | VMware | ACCESS CONTROL |
| VCWN-06-000047 - The system must require an administrator to unlock an account locked due to excessive login failures. | DISA VMware vSphere vCenter Server Version 6 STIG v1r4 | VMware | ACCESS CONTROL |
| WN22-AC-000010 - Windows Server 2022 account lockout duration must be configured to 15 minutes or greater. | DISA Microsoft Windows Server 2022 STIG v2r8 | Windows | ACCESS CONTROL |