The macOS system must set account lockout time to 15 minutes.

STIG ID: APPL-14-000060  |  SRG: SRG-OS-000021-GPOS-00005 | Severity: medium |  CCI: CCI-000044,CCI-002238

Vulnerability Discussion

The macOS must be configured to enforce a lockout time period of at least
15 minutes when the maximum number of failed logon attempts is reached.

This rule protects against malicious users attempting to gain access to the system via brute-force
hacking methods.

Satisfies: SRG-OS-000021-GPOS-00005,SRG-OS-000329-GPOS-00128

Check

Verify the macOS system is configured to set account lockout time to 15 minutes with the
following command:

/usr/bin/pwpolicy -getaccountpolicies 2> /dev/null | /usr/bin/tail +2 | /usr/bin/xmllint --xpath
'//dict/key[text()="autoEnableInSeconds"]/following-sibling::integer[1]/text()' - | /usr/bin/awk '{
if ($1/60 >= 15 ) {print "yes"} else {print "no"}}'

If the result is not "yes", this is a finding.

Fix

Configure the macOS system to set account lockout time to 15 minutes by
installing the "com.apple.mobiledevice.passwordpolicy" configuration profile or by a directory service.