22.06.2016 Views

CIS Microsoft Windows 10 Enterprise RTM (Release 1507) Benchmark

CIS_Microsoft_Windows_10_Enterprise_RTM_Release_1507_Benchmark_v1.0.0

CIS_Microsoft_Windows_10_Enterprise_RTM_Release_1507_Benchmark_v1.0.0

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

1.2 Account Lockout Policy<br />

This section contains recommendations for account lockout policy.<br />

1.2.1 (L1) Set 'Account lockout duration' to '15 or more minute(s)'<br />

(Scored)<br />

Profile Applicability:<br />

Level 1<br />

Level 1 + BitLocker<br />

Description:<br />

This policy setting determines the length of time that must pass before a locked account is<br />

unlocked and a user can try to log on again. The setting does this by specifying the number<br />

of minutes a locked out account will remain unavailable. If the value for this policy setting<br />

is configured to 0, locked out accounts will remain locked out until an administrator<br />

manually unlocks them.<br />

Although it might seem like a good idea to configure the value for this policy setting to a<br />

high value, such a configuration will likely increase the number of calls that the help desk<br />

receives to unlock accounts locked by mistake. Users should be aware of the length of time<br />

a lock remains in place, so that they realize they only need to call the help desk if they have<br />

an extremely urgent need to regain access to their computer.<br />

The recommended state for this setting is: 15 or more minute(s).<br />

Rationale:<br />

A denial of service (DoS) condition can be created if an attacker abuses the Account lockout<br />

threshold and repeatedly attempts to log on with a specific account. Once you configure the<br />

Account lockout threshold setting, the account will be locked out after the specified number<br />

of failed attempts. If you configure the Account lockout duration setting to 0, then the<br />

account will remain locked out until an administrator unlocks it manually.<br />

Audit:<br />

Navigate to the UI Path articulated in the Remediation section and confirm it is set as<br />

prescribed.<br />

47 | P a g e

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!