|
controlAC-7

Unsuccessful Logon Attempts (AC-7)

Enforce a limit of [organization-defined] consecutive invalid logon attempts by a user during a [organization-defined] ; and Automatically [organization-defined] when the maximum number of unsuccessful attempts is exceeded.

Security Baselines

LOWMODERATEHIGH
access-controlauthorizationleast-privilege

Why These Connect

Maps To3

These are equivalent or closely aligned requirements in other frameworks.

Baselined In3

This control is included in the linked security baseline (LOW, MODERATE, or HIGH).

Supports15

These related controls work together — a change to one may affect the others.

Mitigates1

This control helps defend against or reduce the risk of the linked threat technique.

Enhances4

These enhancements add specific capabilities or refinements to the base control.

Threat Coverage(1 ATT&CK techniques)

Cross-Framework Mappings(3)

PR.AA-03PR.AA-03Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ISO 27001ISO/IEC 27001:20221 mappingFinal
NIST OLIR informative reference — SP 800-53 Rev 5 to ISO/IEC 27001:2022
PR.AA-03PR.AA-03Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5

Organization-Defined Parameters(6)

Assignmentorganization-defined number
Assignmentorganization-defined time period
SelectionSelection (one-or-more): lock the account or node for {{ insert: param, ac-07_odp.04 }} / lock the account or node until released by an administrator / delay next logon prompt per {{ insert: param, ac-07_odp.05 }} / notify system administrator / take other {{ insert: param, ac-07_odp.06 }}
Assignmentorganization-defined time period
Assignmentorganization-defined delay algorithm
Assignmentorganization-defined action

Control Enhancements(4)