{"data":{"id":"AC-07","name":"Unsuccessful Logon Attempts","family":"AC","family_name":"Access Control","withdrawn":false,"description":"a. Enforce a limit of [Assignment: organization-defined number] consecutive invalid logon attempts by a user during a [Assignment: organization-defined time period]; and\nb. Automatically [Selection (one or more): lock the account or node for an [Assignment: organization-defined time period]; lock the account or node until released by an administrator; delay next logon prompt per [Assignment: organization-defined delay algorithm]; notify system administrator; take other [Assignment: organization-defined action]] when the maximum number of unsuccessful attempts is exceeded.","supplemental_guidance":"The need to limit unsuccessful logon attempts and take subsequent action when the maximum number of attempts is exceeded applies regardless of whether the logon occurs via a local or network connection. Due to the potential for denial of service, automatic lockouts initiated by systems are usually temporary and automatically release after a predetermined, organization-defined time period. If a delay algorithm is selected, organizations may employ different algorithms for different components of the system based on the capabilities of those components. Responses to unsuccessful logon attempts may be implemented at the operating system and the application levels. Organization-defined actions that may be taken when the number of allowed consecutive invalid logon attempts is exceeded include prompting the user to answer a secret question in addition to the username and password, invoking a lockdown mode with limited user capabilities (instead of full lockout), allowing users to only logon from specified Internet Protocol (IP) addresses, requiring a CAPTCHA to prevent automated attacks, or applying user profiles such as location, time of day, IP address, device, or Media Access Control (MAC) address. If automatic system lockout or execution of a delay algorithm is not implemented in support of the availability objective, organizations consider a combination of other actions to help prevent brute force attacks. In addition to the above, organizations can prompt users to respond to a secret question before the number of allowed unsuccessful logon attempts is exceeded. Automatically unlocking an account after a specified period of time is generally not permitted. However, exceptions may be required based on operational mission or need.","enhancements":[{"id":"AC-07(01)","name":"Automatic Account Lock","withdrawn":true,"incorporated_into":["AC-07"]},{"id":"AC-07(02)","name":"Purge or Wipe Mobile Device","statement":"Purge or wipe information from [Assignment: organization-defined mobile devices] based on [Assignment: organization-defined purging or wiping requirements and techniques] after [Assignment: organization-defined number] consecutive, unsuccessful device logon attempts.","baselines":[]},{"id":"AC-07(03)","name":"Biometric Attempt Limiting","statement":"Limit the number of unsuccessful biometric logon attempts to [Assignment: organization-defined number].","baselines":[]},{"id":"AC-07(04)","name":"Use of Alternate Authentication Factor","statement":"a. Allow the use of [Assignment: organization-defined authentication factors] that are different from the primary authentication factors after the number of organization-defined consecutive invalid logon attempts have been exceeded; and\nb. Enforce a limit of [Assignment: organization-defined number] consecutive invalid logon attempts through use of the alternative factors by a user during a [Assignment: organization-defined time period].","baselines":[]}],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"nist_800_53":{"rev5":{"id":"AC-07","name":"Unsuccessful Logon Attempts","description":"a. Enforce a limit of [Assignment: organization-defined number] consecutive invalid logon attempts by a user during a [Assignment: organization-defined time period]; and\nb. Automatically [Selection (one or more): lock the account or node for an [Assignment: organization-defined time period]; lock the account or node until released by an administrator; delay next logon prompt per [Assignment: organization-defined delay algorithm]; notify system administrator; take other [Assignment: organization-defined action]] when the maximum number of unsuccessful attempts is exceeded.","discussion":"The need to limit unsuccessful logon attempts and take subsequent action when the maximum number of attempts is exceeded applies regardless of whether the logon occurs via a local or network connection. Due to the potential for denial of service, automatic lockouts initiated by systems are usually temporary and automatically release after a predetermined, organization-defined time period. If a delay algorithm is selected, organizations may employ different algorithms for different components of the system based on the capabilities of those components. Responses to unsuccessful logon attempts may be implemented at the operating system and the application levels. Organization-defined actions that may be taken when the number of allowed consecutive invalid logon attempts is exceeded include prompting the user to answer a secret question in addition to the username and password, invoking a lockdown mode with limited user capabilities (instead of full lockout), allowing users to only logon from specified Internet Protocol (IP) addresses, requiring a CAPTCHA to prevent automated attacks, or applying user profiles such as location, time of day, IP address, device, or Media Access Control (MAC) address. If automatic system lockout or execution of a delay algorithm is not implemented in support of the availability objective, organizations consider a combination of other actions to help prevent brute force attacks. In addition to the above, organizations can prompt users to respond to a secret question before the number of allowed unsuccessful logon attempts is exceeded. Automatically unlocking an account after a specified period of time is generally not permitted. However, exceptions may be required based on operational mission or need.","related_controls":["AC-02","AC-09","AU-02","AU-06","IA-05"],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"baseline_privacy":false,"new_in_rev5":false,"changes_from_rev4":"Parameter includes additional selection options when the number of allowed consecutive invalid logon attempts threshold is exceeded Discussion amplifies the control text with examples of addition actions to help prevent brute force attacks"}},"compliance_mappings":{"iso_27001_2022":["A.8.5"],"iso_27002_2022":["5.15"],"cobit_2019":["DSS05"],"pci_dss_v4":[],"nist_csf_2":["PR.AA-03"],"cis_controls_v8":["CIS 4.10"],"soc2_tsc":[],"finos_ccc":[],"iso_42001_2023":[],"iec_62443":[],"asd_e8":[],"nis2":["Art. 21(2)(i)"],"apra_cps_234":[],"mas_trm":["9"],"pra_op_resilience":[],"bsi_grundschutz":["ORP.4"],"anssi":["Hygiene.10","Hygiene.12","SecNumCloud.10.5"],"osfi_b13":["B-13.3.2"],"finma_circular":["IV.B.d(59)","IV.C(61)"],"gdpr":["Art.32(1)(b)","Art.32(1)(d)"],"dora":["Art.9(4)(c)"],"bio2":["5.15"],"rbi_csf":["Annex1.8"],"fisc":["FISC.T2"],"lgpd_bcb":[],"hkma_tme1":[],"mlps_2":["8.1.4.1"],"dnb_good_practice":["DNB.17.2"],"cra":["CRA.I.2d"],"swift_cscf":["SWIFT.4.1"],"cbb_tm":["TM-6"],"cbuae":["CR-4"],"nca_ecc":["2-2"],"qatar_nia":["AC"],"sama_csf":["3.1"],"uae_ia":["T9"],"bog_cisd":["CISD-VIII"],"bom_ctrm":["3.3"],"cbe_csf":["CTO-1"],"cbn_csf":["Part3.2"],"popia":["s19"],"sa_js2":["JS2-7.1","JS2-8.1"],"bot_cyber":["Ch2.2","Ch8.2"],"cpmi_pfmi":["CG.PR"],"eba_ict":["3.4.2"],"ecb_croe":["CROE.2.3.1"],"ffiec_is":["II.C.15"],"hipaa_sr":["§164.308(a)(5)(ii)(C)","§164.312(a)(1)"],"iosco_cyber":["PROT-1"],"sebi_cscrf":["PR.AA"],"cmmc_2":["AC"],"nerc_cip":[],"nrc_73_54":["RG5.71-A-AC"],"tsa_psd":["SD-2 Sec B"],"ieee_1686":["5.7"],"ferc_cip":[],"doe_c2m2":["ACCESS"],"api_1164":["Sec 6"],"awia":["AWWA Sec 3"],"iaea_nss":["Sec 5.3"],"pci_pts":[],"fips_140":["FIPS 140-3 §7.4"],"cbest":[],"tiber_eu":[],"pci_hsm":[],"common_criteria":["CC Part 2 — FIA","CC Part 2 — FRU/FTA/FTP"],"isae_3402":[],"fca_sysc_13":["SYSC 13.7.3"],"fda_21_cfr_11":["§11.10(d)","§11.200(a)(1)(ii)"],"fda_cyber":["SA-1"],"hitrust_csf":["01.c"],"iso_27799":["9.5"],"lloyds_ms":["MS8.3"],"naic_ds":["4-access"],"nhs_dspt":["NDG-4.3"],"pra_ss1_23":[],"solvency_ii":["EIOPA-ICT-4.4"],"owasp_masvs_v2":["MASVS-AUTH-2"],"csa_ccm_v4":[],"csa_aicm":[],"ccss_v9":[],"mica":[],"basel_sco60":[],"bssc":[],"sec_custody_digital":[],"dpdpa":[]},"attack_techniques":[{"id":"T1021","name":"Remote Services","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Account lockout after consecutive failed login attempts prevents adversaries from systematically testing credentials against remote service endpoints such as RDP and SSH for lateral movement."},{"id":"T1110","name":"Brute Force","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Enforcing limits on consecutive unsuccessful login attempts directly counters brute force attacks by locking accounts or introducing progressive delays that make exhaustive password testing infeasible."},{"id":"T1133","name":"External Remote Services","tactics":["initial-access","persistence"],"mapping_type":"mitigates","mapping_rationale":"Failed login attempt limits on VPN gateways and external remote access portals lock accounts after repeated authentication failures, preventing sustained credential guessing against externally exposed services."},{"id":"T1530","name":"Data from Cloud Storage","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Account lockout policies on cloud storage authentication endpoints prevent adversaries from systematically testing credentials to gain access to cloud-hosted data repositories."},{"id":"T1556","name":"Modify Authentication Process","tactics":["credential-access","defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Monitoring unsuccessful authentication attempts against modified authentication mechanisms detects adversary-introduced backdoors that generate unusual patterns of authentication failures and successes."},{"id":"T1021.001","name":"Remote Desktop Protocol","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Account lockout after failed RDP authentication attempts prevents adversaries from brute-forcing Remote Desktop credentials, blocking automated password attacks against RDP-exposed systems."},{"id":"T1021.004","name":"SSH","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"SSH account lockout or progressive delays after failed login attempts prevent adversaries from systematically testing SSH passwords for lateral movement to Linux and Unix systems."},{"id":"T1078.002","name":"Domain Accounts","tactics":["defense-evasion","initial-access","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Failed login attempt limits on domain authentication prevent adversaries from systematically testing compromised domain credentials across multiple domain-joined systems and services."},{"id":"T1078.004","name":"Cloud Accounts","tactics":["defense-evasion","initial-access","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Account lockout policies on cloud identity providers lock cloud accounts after consecutive failed authentications, preventing brute force attacks against cloud-based identities and services."},{"id":"T1110.001","name":"Password Guessing","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Account lockout after consecutive failed attempts directly prevents online password guessing by locking accounts before adversaries can exhaust their password dictionaries against live authentication endpoints."},{"id":"T1110.002","name":"Password Cracking","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"While password cracking occurs offline, lockout policies limit the online validation of cracked credentials and encourage stronger password requirements that increase offline cracking complexity."},{"id":"T1110.003","name":"Password Spraying","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Failed login thresholds across multiple accounts detect password spraying patterns where adversaries test a small number of common passwords against many accounts simultaneously."},{"id":"T1110.004","name":"Credential Stuffing","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Account lockout after consecutive failed attempts blocks credential stuffing campaigns by locking targeted accounts before adversaries can successfully validate stolen credential pairs from data breaches."},{"id":"T1556.001","name":"Domain Controller Authentication","tactics":["credential-access","defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Monitoring unsuccessful authentication patterns at domain controllers detects backdoored authentication processes that generate anomalous login failure patterns inconsistent with normal user behavior."},{"id":"T1556.003","name":"Pluggable Authentication Modules","tactics":["credential-access","defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Failed login tracking against PAM-authenticated services detects malicious PAM modules that alter authentication behavior, as backdoored modules may produce unusual authentication failure patterns."},{"id":"T1556.004","name":"Network Device Authentication","tactics":["credential-access","defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Monitoring unsuccessful login attempts on network devices detects backdoored authentication mechanisms that generate authentication anomalies when adversary-modified authentication processes fail for legitimate users."}],"metadata":{"last_reviewed":"2026-10-03","review_notes":"2026-10-02: iso_27001_2022 clauses taken from NIST's SP 800-53 Rev 5 to ISO/IEC 27001:2022 crosswalk (OLIR, v1.0.0). OSA had none. 2026-10-03: nist_csf_2 PR.AA-03 added from NIST's CSF 2.0 to SP 800-53 Rev 5.2.0 crosswalk (OLIR entry 186), which OSA's mapping now takes as its base.","mapping_status":"complete"},"function":"preventative","used_by_patterns":["SP-001","SP-002","SP-005","SP-008","SP-016","SP-019","SP-029","SP-030","SP-031","SP-032","SP-033","SP-050"]}}