HomeControl Library › 3.1.8
3.1 Access Control1 ptPOA&M-eligible

3.1.8 — Limit failed logons

Limit unsuccessful logon attempts.

Lock out accounts after too many bad password attempts.

What it actually means

Limit unsuccessful logon attempts to slow down password-guessing and brute-force attacks. Set an account-lockout threshold and lockout duration across your systems — workstations, servers, VPN, and cloud identity.

Pass or fail — an assessor needs a "yes" to each

What to have ready

Where teams trip up

See where this control puts your score

Run all 110 requirements free in about 10 minutes.

Calculate your SPRS score →

Connected requirements

← Back to the Control Library