CIS Controls CIS-4.10

Enforce automatic device lockout following a predetermined threshold of local failed authentication attempts on portable end-user devices, where supported. For laptops, do not allow more than 20 failed authentication attempts; for tablets and smartphones, no more than 10 failed authentication attempts. Example implementations include Microsoft® InTune Device Lock and Apple® Configuration Profile maxFailedAttempts.

Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
CIS-4.10 Enforce Automatic Device Lockout on Portable End-User Devices mitigates T1110.004 Credential Stuffing
Comments
Automatic device lockout limits the number of consecutive authentication attempts that can be made against a portable device, directly reducing the likelihood that repeated breached username password attempts will succeed.
References
    CIS-4.10 Enforce Automatic Device Lockout on Portable End-User Devices mitigates T1110.003 Password Spraying
    Comments
    Automatic device lockout limits the number of consecutive authentication attempts that can be made against a portable device, directly reducing the likelihood that repeated online password attempts will succeed.
    References
      CIS-4.10 Enforce Automatic Device Lockout on Portable End-User Devices mitigates T1110.001 Password Guessing
      Comments
      Automatic device lockout limits the number of consecutive authentication attempts that can be made against a portable device, directly reducing the likelihood that repeated online password attempts will succeed.
      References
        CIS-4.10 Enforce Automatic Device Lockout on Portable End-User Devices mitigates T1110 Brute Force
        Comments
        Automatic device lockout limits the number of consecutive authentication attempts that can be made against a portable device, directly reducing the likelihood that repeated online password attempts will succeed.
        References