Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
3.1.8OFFICIAL STATEMENT BELOWDERIVED REQUIREMENTPENDING NIST SME REVIEW

3.1.8Unsuccessful logon attempts

3.1 Access Control · NIST SP 800-171 Rev. 2 · The heading label is this site's navigational shorthand; the official language is the statement below.

Independent interpretation

What this requirement is after

Password guessing gets a small number of tries, then the door slows or shuts. Lockout or progressive throttling after failed attempts turns brute force from an overnight certainty into a noisy failure.

Mapped practices

Brilliant at the Basics practices that support this requirement

Doing the work

Implementation considerations and evidence

Implementation considerationsIndependent guidance — tailor to your environment
  • Configure the threshold and lockout behavior in each place authentication happens — identity provider, operating systems, VPN — and record what you chose.
  • Prefer throttling or time-boxed lockout over permanent lockout, which converts the requirement into a denial-of-service tool against your own staff.
What operating evidence looks likeRecords worth retaining, not a submission checklist
  • Lockout or smart-lockout policy exports from each authentication point
  • Sampled lockout events showing the mechanism operating
Artifacts

Templates and worksheets with a mapped relationship

No artifact in the library names this requirement yet. The library index groups everything by category and practice.

The other revision

Where this lands in Rev. 3

Provenance

Sources and review status

Primary sourcesNIST SP 800-171 Rev. 2 — Protecting CUI in Nonfederal Systems · NIST SP 800-171A — Assessing Security Requirements for CUI
Review statusPending NIST SME review
Content version1.0
Updated