commoncriteria / operatingsystem

Protection Profile for Operating Systems
The Unlicense
9 stars 6 forks source link

Config Annex - Specify when to re-activate disabled accounts #111

Open shawndwells opened 6 years ago

shawndwells commented 6 years ago

Config Annex reflects requirement to lock accounts after 3 attempts in 15 minutes.

The lockout duration needs to be defined. Lack of specification leads to interpretation accounts should be disabled until administrator reactivation. That will significantly impact administrative burden across US Gov.