# AC-07 Unsuccessful Logon Attempts

NIST SP 800-53 control. Family: AC Access Control. Function: preventative. Baselines: low, moderate, high. Mapping licence: CC BY-SA 4.0.

Statement: a. Enforce a limit of [Assignment: organization-defined number] consecutive invalid logon attempts by a user during a [Assignment: organization-defined time period]; and b. Automatically [Selection (one or more): lock the account or node for an [Assignment: organization-defined time period]; lock the account or node until released by an administrator; delay next logon prompt per [Assignment: organization-defined delay algorithm]; notify system administrator; take other [Assignment: organization-defined action]] when the maximum number of unsuccessful attempts is exceeded.
Guidance: The need to limit unsuccessful logon attempts and take subsequent action when the maximum number of attempts is exceeded applies regardless of whether the logon occurs via a local or network connection. Due to the potential for denial of service, automatic lockouts initiated by systems are usually temporary and automatically release after a predetermined, organization-defined time period. If a delay algorithm is selected, organizations may employ different algorithms for different components of the system based on the capabilities of those components. Responses to unsuccessful logon attempts may be implemented at the operating system and the application levels. Organization-defined actions that may be taken when the number of allowed consecutive invalid logon attempts is exceeded include prompting the user to answer a secret question in addition to the username and password, invoking a lockdown mode with limited user capabilities (instead of full lockout), allowing users to only logon from specified Internet Protocol (IP) addresses, requiring a CAPTCHA to prevent automated attacks, or applying user profiles such as location, time of day, IP address, device, or Media Access Control (MAC) address. If automatic system lockout or execution of a delay algorithm is not implemented in support of the availability objective, organizations consider a combination of other actions to help prevent brute force attacks. In addition to the above, organizations can prompt users to respond to a secret question before the number of allowed unsuccessful logon attempts is exceeded. Automatically unlocking an account after a specified period of time is generally not permitted. However, exceptions may be required based on operational mission or need.

## Enhancements (3)
- AC-07(02) Purge or Wipe Mobile Device
- AC-07(03) Biometric Attempt Limiting
- AC-07(04) Use of Alternate Authentication Factor
Withdrawn by NIST: AC-07(01) (now in AC-07).
Each enhancement's statement: /api/v1/controls/AC-07?fields=enhancements

## Patterns that use it (12)
- Critical (2): SP-008 Public Web Server Pattern; SP-030 API Security
- Important (4): SP-001 Client Module; SP-002 Server Module; SP-019 Secure Ad-Hoc File Exchange Pattern; SP-032 Modern Authentication
- Standard (6): SP-005 SOA Internal Service Usage Pattern; SP-016 DMZ Module; SP-029 Zero Trust Architecture; SP-031 Security Monitoring and Response; SP-033 Passkey Authentication; SP-050 Mobile Security Architecture (draft)

## Clauses by framework (60 frameworks)
- iso_27001_2022: A.8.5
- iso_27002_2022: 5.15
- cobit_2019: DSS05
- nist_csf_2: PR.AA-03
- cis_controls_v8: CIS 4.10
- nis2: Art. 21(2)(i)
- mas_trm: 9
- bsi_grundschutz: ORP.4
- anssi: Hygiene.10, Hygiene.12, SecNumCloud.10.5
- osfi_b13: B-13.3.2
- finma_circular: IV.B.d(59), IV.C(61)
- gdpr: Art.32(1)(b), Art.32(1)(d)
- dora: Art.9(4)(c)
- bio2: 5.15
- rbi_csf: Annex1.8
- fisc: FISC.T2
- mlps_2: 8.1.4.1
- dnb_good_practice: DNB.17.2
- cra: CRA.I.2d
- swift_cscf: SWIFT.4.1
- cbb_tm: TM-6
- cbuae: CR-4
- nca_ecc: 2-2
- qatar_nia: AC
- sama_csf: 3.1
- uae_ia: T9
- bog_cisd: CISD-VIII
- bom_ctrm: 3.3
- cbe_csf: CTO-1
- cbn_csf: Part3.2
- popia: s19
- sa_js2: JS2-7.1, JS2-8.1
- bot_cyber: Ch2.2, Ch8.2
- cpmi_pfmi: CG.PR
- eba_ict: 3.4.2
- ecb_croe: CROE.2.3.1
- ffiec_is: II.C.15
- hipaa_sr: §164.308(a)(5)(ii)(C), §164.312(a)(1)
- iosco_cyber: PROT-1
- sebi_cscrf: PR.AA
- cmmc_2: AC
- nrc_73_54: RG5.71-A-AC
- tsa_psd: SD-2 Sec B
- ieee_1686: 5.7
- doe_c2m2: ACCESS
- api_1164: Sec 6
- awia: AWWA Sec 3
- iaea_nss: Sec 5.3
- fips_140: FIPS 140-3 §7.4
- common_criteria: CC Part 2 — FIA, CC Part 2 — FRU/FTA/FTP
- fca_sysc_13: SYSC 13.7.3
- fda_21_cfr_11: §11.10(d), §11.200(a)(1)(ii)
- fda_cyber: SA-1
- hitrust_csf: 01.c
- iso_27799: 9.5
- lloyds_ms: MS8.3
- naic_ds: 4-access
- nhs_dspt: NDG-4.3
- solvency_ii: EIOPA-ICT-4.4
- owasp_masvs_v2: MASVS-AUTH-2
OSA's mapping for iso_27001_2022 and nist_csf_2 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/AC-07
- Clauses only: /api/v1/controls/AC-07?fields=mappings
- Page for people: /controls/ac-07/
