← Controls / AC

AC-07 Unsuccessful Logon Attempts

Access Control

Low Moderate High

Description

a. Enforce a limit of [Assignment: organization-defined number] consecutive invalid logon attempts by a user during a [Assignment: organization-defined time period]; and b. Automatically [Selection (one or more): lock the account or node for an [Assignment: organization-defined time period]; lock the account or node until released by an administrator; delay next logon prompt per [Assignment: organization-defined delay algorithm]; notify system administrator; take other [Assignment: organization-defined action]] when the maximum number of unsuccessful attempts is exceeded.

Supplemental Guidance

The need to limit unsuccessful logon attempts and take subsequent action when the maximum number of attempts is exceeded applies regardless of whether the logon occurs via a local or network connection. Due to the potential for denial of service, automatic lockouts initiated by systems are usually temporary and automatically release after a predetermined, organization-defined time period. If a delay algorithm is selected, organizations may employ different algorithms for different components of the system based on the capabilities of those components. Responses to unsuccessful logon attempts may be implemented at the operating system and the application levels. Organization-defined actions that may be taken when the number of allowed consecutive invalid logon attempts is exceeded include prompting the user to answer a secret question in addition to the username and password, invoking a lockdown mode with limited user capabilities (instead of full lockout), allowing users to only logon from specified Internet Protocol (IP) addresses, requiring a CAPTCHA to prevent automated attacks, or applying user profiles such as location, time of day, IP address, device, or Media Access Control (MAC) address. If automatic system lockout or execution of a delay algorithm is not implemented in support of the availability objective, organizations consider a combination of other actions to help prevent brute force attacks. In addition to the above, organizations can prompt users to respond to a secret question before the number of allowed unsuccessful logon attempts is exceeded. Automatically unlocking an account after a specified period of time is generally not permitted. However, exceptions may be required based on operational mission or need.

Changes from Rev 4

Parameter includes additional selection options when the number of allowed consecutive invalid logon attempts threshold is exceeded Discussion amplifies the control text with examples of addition actions to help prevent brute force attacks

Enhancements (3)

What NIST adds to this control. Select one to read its statement.

AC-07(02) Purge or Wipe Mobile Device

Purge or wipe information from [Assignment: organization-defined mobile devices] based on [Assignment: organization-defined purging or wiping requirements and techniques] after [Assignment: organization-defined number] consecutive, unsuccessful device logon attempts.

AC-07(03) Biometric Attempt Limiting

Limit the number of unsuccessful biometric logon attempts to [Assignment: organization-defined number].

AC-07(04) Use of Alternate Authentication Factor

a. Allow the use of [Assignment: organization-defined authentication factors] that are different from the primary authentication factors after the number of organization-defined consecutive invalid logon attempts have been exceeded; and b. Enforce a limit of [Assignment: organization-defined number] consecutive invalid logon attempts through use of the alternative factors by a user during a [Assignment: organization-defined time period].

Withdrawn by NIST:

  • AC-07(01) Automatic Account Lock, now in AC-07

Compliance Mappings

ISO 27001:2022

A.8.5

ISO 27002:2022

5.15

COBIT 2019

DSS05

CIS Controls v8

CIS 4.10

NIST CSF 2.0

PR.AA-03

NIS2 Directive

Art. 21(2)(i)

MAS TRM

9

BSI IT-Grundschutz

ORP.4

ANSSI

Hygiene.10Hygiene.12SecNumCloud.10.5

FINMA Circular 2023/1

IV.B.d(59)IV.C(61)

OSFI B-13

B-13.3.2

EU GDPR

Art.32(1)(b)Art.32(1)(d)

EU DORA

Art.9(4)(c)

BIO2

5.15

RBI CSF

Annex1.8

FISC Security Guidelines

FISC.T2

MLPS 2.0

8.1.4.1

DNB Good Practice

DNB.17.2

EU CRA

CRA.I.2d

SWIFT CSCF

SWIFT.4.1

SAMA CSF

3.1

NCA ECC

2-2

UAE IA

T9

CBB TM

TM-6

Qatar NIA

AC

CBUAE

CR-4

CBE CSF

CTO-1

SA JS2

JS2-7.1JS2-8.1

CBN CSF

Part3.2

BoG CISD

CISD-VIII

POPIA

s19

BoM CTRM

3.3

IOSCO Cyber Resilience

PROT-1

CPMI-IOSCO PFMI

CG.PR

FFIEC IS

II.C.15

HIPAA Security Rule

§164.308(a)(5)(ii)(C)§164.312(a)(1)

ECB CROE

CROE.2.3.1

EBA ICT Guidelines

3.4.2

SEBI CSCRF

PR.AA

BOT Cyber Resilience

Ch2.2Ch8.2

CMMC 2.0

AC

10 CFR 73.54

RG5.71-A-AC

TSA Pipeline SD

SD-2 Sec B

IEEE 1686-2022

5.7

DOE C2M2 v2.1

ACCESS

API 1164

Sec 6

AWIA

AWWA Sec 3

IAEA NSS 17-T

Sec 5.3

FIPS 140-3

FIPS 140-3 §7.4

Common Criteria

CC Part 2 — FIACC Part 2 — FRU/FTA/FTP

Solvency II

EIOPA-ICT-4.4

Lloyd's Minimum Standards

MS8.3

NAIC Insurance Data Security

4-access

FCA SYSC 13

SYSC 13.7.3

HITRUST CSF v11

01.c

FDA 21 CFR Part 11

§11.10(d)§11.200(a)(1)(ii)

FDA Cybersecurity Guidance

SA-1

ISO 27799

9.5

NHS DSPT

NDG-4.3

OWASP MASVS v2.1

MASVS-AUTH-2

ISO 17799 (legacy)

11.5.1

COBIT 4.1 (legacy)

None.