PlumbTrackLive demoGRC Risk System

← internal audit

Audit — AC-7 — Unsuccessful Logon Attempts

Framework: NIST SP 800-53 Rev.5 AC-7 · Mark each check Pass / Fail / N/A; a Fail is a finding to remediate. · open the item

0 pass · 0 finding(s) · 0 N/A · 0 of 6 checked
Examine Examine the authentication policy and system/IdP configuration to confirm a maximum number of consecutive invalid logon attempts is defined (e.g., 5) along with the lockout duration or lock-until-admin-release action.
Test On a representative system, enter invalid credentials up to and beyond the defined threshold with a test account and confirm the account (or node) is locked/disabled as configured.
Test After triggering a lockout, confirm the lock persists for the defined time period or until explicitly released by an administrator, rather than clearing prematurely.
Examine Confirm the lockout/threshold setting is applied consistently across in-scope systems (e.g., via domain GPO, IdP/conditional-access policy, and standalone system baselines) and not left at permissive defaults.
Interview Ask help desk/administrators to describe the account unlock procedure and confirm identity is verified before an account is unlocked or the counter reset.
Examine Confirm lockout events generate log entries and, where required, alerts, and that these are captured for monitoring and investigation.