Skip to content

The macOS system must set account lockout time to 15 minutes.

An XCCDF Rule

Description

The macOS system must be configured to enforce a lockout time period of at least 15 minutes when the maximum number of failed login attempts is reached. This rule protects against malicious users attempting to gain access to the system via brute-force hacking methods. Satisfies: SRG-OS-000021-GPOS-00005, SRG-OS-000329-GPOS-00128

ID
SV-268440r1034260_rule
Version
APPL-15-000060
Severity
Medium
References
Updated

Remediation Templates

A Manual Procedure

Configure the macOS system to set account lockout time to 15 minutes by installing the "com.apple.mobiledevice.passwordpolicy" configuration profile or by a directory service.