Enforce automatic device lockout following a predetermined threshold of local failed authentication attempts on portable end-user devices, where supported. For laptops, do not allow more than 20 failed authentication attempts; for tablets and smartphones, no more than 10 failed authentication attempts. Example implementations include Microsoft® InTune Device Lock and Apple® Configuration Profile maxFailedAttempts.
| Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
|---|---|---|---|---|---|
| CIS-4.10 | Enforce Automatic Device Lockout on Portable End-User Devices | mitigates | T1110.004 | Credential Stuffing |
Comments
Automatic device lockout limits the number of consecutive authentication attempts that can be made against a portable device, directly reducing the likelihood that repeated breached username password attempts will succeed.
References
|
| CIS-4.10 | Enforce Automatic Device Lockout on Portable End-User Devices | mitigates | T1110.003 | Password Spraying |
Comments
Automatic device lockout limits the number of consecutive authentication attempts that can be made against a portable device, directly reducing the likelihood that repeated online password attempts will succeed.
References
|
| CIS-4.10 | Enforce Automatic Device Lockout on Portable End-User Devices | mitigates | T1110.001 | Password Guessing |
Comments
Automatic device lockout limits the number of consecutive authentication attempts that can be made against a portable device, directly reducing the likelihood that repeated online password attempts will succeed.
References
|
| CIS-4.10 | Enforce Automatic Device Lockout on Portable End-User Devices | mitigates | T1110 | Brute Force |
Comments
Automatic device lockout limits the number of consecutive authentication attempts that can be made against a portable device, directly reducing the likelihood that repeated online password attempts will succeed.
References
|