The CA VM:Secure JOURNAL Facility parameters must be set for lockout after 3 attempts.
An XCCDF Rule
Description
By limiting the number of failed logon attempts, the risk of unauthorized system access via user password guessing, otherwise known as brute-force attacks, is reduced. Limits are imposed by locking the account.
- ID
- SV-237901r649543_rule
- Version
- IBMZ-VM-000045
- Severity
- Medium
- References
- Updated
Remediation Templates
A Manual Procedure
Edit the SECURITY CONFIG file:
vmsecure config security
Configure a JOURNAL record in the SECURITY CONFIG file as follows: