SRG-OS-000329-GPOS-00128 Controls

STIG IDVersionTitleProduct
ALMA-09-008160V1R3AlmaLinux OS 9 must maintain an account lock until the locked account is manually released by an administrator; and not automatically after a set time.
ALMA-09-008270V1R3AlmaLinux OS 9 must ensure account locks persist across reboots.
ALMA-09-008380V1R3AlmaLinux OS 9 must configure the appropriate SELinux context on the nondefault faillock tally directory.
APPL-13-000022V1R5The macOS system must enforce the limit of three consecutive invalid logon attempts by a user before the user account is locked.
OL07-00-010330V3R3The Oracle Linux operating system must lock the associated account after three unsuccessful root logon attempts are made within a 15-minute period.
OL09-00-002416V1R2OL 9 must automatically lock an account when three unsuccessful logon attempts occur during a 15-minute time period.
OL09-00-002417V1R2OL 9 must maintain an account lock until the locked account is released by an administrator.
OL09-00-003020V1R2OL 9 must automatically lock an account when three unsuccessful logon attempts occur.
OL09-00-003021V1R2OL 9 must automatically lock the root account until the root account is released by an administrator when three unsuccessful logon attempts occur during a 15-minute time period.
RHEL-07-010320V3R9The Red Hat Enterprise Linux operating system must be configured to lock accounts for a minimum of 15 minutes after three unsuccessful logon attempts within a 15-minute timeframe.
RHEL-07-010330V3R9The Red Hat Enterprise Linux operating system must lock the associated account after three unsuccessful root logon attempts are made within a 15-minute period.
RHEL-09-411075V2R5RHEL 9 must automatically lock an account when three unsuccessful logon attempts occur.
RHEL-09-411080V2R5RHEL 9 must automatically lock the root account until the root account is released by an administrator when three unsuccessful logon attempts occur during a 15-minute time period.
RHEL-09-411085V2R5RHEL 9 must automatically lock an account when three unsuccessful logon attempts occur during a 15-minute time period.
RHEL-09-411090V2R5RHEL 9 must maintain an account lock until the locked account is released by an administrator.
UBTU-20-010072V2R3The Ubuntu operating system must automatically lock an account until the locked account is released by an administrator when three unsuccessful logon attempts have been made.
WN10-AC-000005V3R4Windows 10 account lockout duration must be configured to 15 minutes or greater.
WN11-AC-000005V2R4Windows 11 account lockout duration must be configured to 15 minutes or greater.
WN16-AC-000010V2R9Windows 2016 account lockout duration must be configured to 15 minutes or greater.
WN19-AC-000010V3R4Windows Server 2019 account lockout duration must be configured to 15 minutes or greater.
WN22-AC-000010V2R5Windows Server 2022 account lockout duration must be configured to 15 minutes or greater.