<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Account lockout, NIST/ISO/HIPAA etc. in Industry News</title>
    <link>https://community.isc2.org/t5/Industry-News/Account-lockout-NIST-ISO-HIPAA-etc/m-p/14052#M1515</link>
    <description>&lt;P&gt;You really should look at what works best for your agency. A framework is just that a frame that you make work for your needs. The higher your need for security the stricter your controls are going to be. If you have a user base that is constantly forgetting passwords and you set it too strict (i.e 3 fails before lockout instead of 5), your helpdesk is going to be overwhelmed OR they will just write them down, which defeats your security measures.&lt;/P&gt;</description>
    <pubDate>Tue, 28 Aug 2018 10:56:42 GMT</pubDate>
    <dc:creator>CISOScott</dc:creator>
    <dc:date>2018-08-28T10:56:42Z</dc:date>
    <item>
      <title>Account lockout, NIST/ISO/HIPAA etc.</title>
      <link>https://community.isc2.org/t5/Industry-News/Account-lockout-NIST-ISO-HIPAA-etc/m-p/14006#M1506</link>
      <description>&lt;P&gt;Hello Security folks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Wanted to get your opinion about the account lockout control. Especially I am interested in some exact threshold numbers if available in any of the security related frameworks out there. I checked a few but neither NIST, nor PCI, nor HIPAA or the ISO have e recommendation of for example 3/5/10. I know it's up to the company and a lot of things to be considered however - do you know if there's framework where that is given a value?&lt;/P&gt;</description>
      <pubDate>Mon, 27 Aug 2018 13:49:24 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Account-lockout-NIST-ISO-HIPAA-etc/m-p/14006#M1506</guid>
      <dc:creator>Deyan</dc:creator>
      <dc:date>2018-08-27T13:49:24Z</dc:date>
    </item>
    <item>
      <title>Re: Account lockout, NIST/ISO/HIPAA etc.</title>
      <link>https://community.isc2.org/t5/Industry-News/Account-lockout-NIST-ISO-HIPAA-etc/m-p/14032#M1509</link>
      <description>&lt;P&gt;Deyan,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The control should be based on organizational policy (and risk). There are some best practice documents that include recommended values, however; these are just recommendations. If your organization does not have a policy (or regulatory requirement) that defines a value, perform a risk assessment over the control and let management make the decision.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Two best practices you can review are the Center For Internet Security Benchmarks and the DISA Security Technical Implementation Guides. For example, CIS recommends a lockout threshold of 10 or less for Windows Server 2012 R2 (this is just an example, you should review the applicable benchmark).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here are the links:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisecurity.org/" target="_blank"&gt;https://www.cisecurity.org/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://iase.disa.mil/stigs/Pages/index.aspx" target="_blank"&gt;https://iase.disa.mil/stigs/Pages/index.aspx&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this helps point you in the right direction for some research.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Aug 2018 18:21:57 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Account-lockout-NIST-ISO-HIPAA-etc/m-p/14032#M1509</guid>
      <dc:creator>Cousy14</dc:creator>
      <dc:date>2018-08-27T18:21:57Z</dc:date>
    </item>
    <item>
      <title>Re: Account lockout, NIST/ISO/HIPAA etc.</title>
      <link>https://community.isc2.org/t5/Industry-News/Account-lockout-NIST-ISO-HIPAA-etc/m-p/14050#M1513</link>
      <description>Hi Deyan,&lt;BR /&gt;the PCI DSS standard has two requirements about account lockout policy:&lt;BR /&gt;Req 8.1.6 - "Limit repeated access attempts by locking out the user ID after not more than six attempts."&lt;BR /&gt;Req 8.1.7 - "Set the lockout duration to a minimum of 30 minutes or until an administrator enables the user ID."&lt;BR /&gt;I hope this is helpful for you.&lt;BR /&gt;&lt;BR /&gt;Best regards,&lt;BR /&gt;Luciano</description>
      <pubDate>Tue, 28 Aug 2018 07:52:34 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Account-lockout-NIST-ISO-HIPAA-etc/m-p/14050#M1513</guid>
      <dc:creator>Lucio</dc:creator>
      <dc:date>2018-08-28T07:52:34Z</dc:date>
    </item>
    <item>
      <title>Re: Account lockout, NIST/ISO/HIPAA etc.</title>
      <link>https://community.isc2.org/t5/Industry-News/Account-lockout-NIST-ISO-HIPAA-etc/m-p/14052#M1515</link>
      <description>&lt;P&gt;You really should look at what works best for your agency. A framework is just that a frame that you make work for your needs. The higher your need for security the stricter your controls are going to be. If you have a user base that is constantly forgetting passwords and you set it too strict (i.e 3 fails before lockout instead of 5), your helpdesk is going to be overwhelmed OR they will just write them down, which defeats your security measures.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Aug 2018 10:56:42 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Account-lockout-NIST-ISO-HIPAA-etc/m-p/14052#M1515</guid>
      <dc:creator>CISOScott</dc:creator>
      <dc:date>2018-08-28T10:56:42Z</dc:date>
    </item>
    <item>
      <title>Re: Account lockout, NIST/ISO/HIPAA etc.</title>
      <link>https://community.isc2.org/t5/Industry-News/Account-lockout-NIST-ISO-HIPAA-etc/m-p/14053#M1516</link>
      <description>&lt;P&gt;Agree with all of you - just needed to know if there are any exact values in the public papers somewhere. THank you all for your comments.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Aug 2018 11:36:17 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Account-lockout-NIST-ISO-HIPAA-etc/m-p/14053#M1516</guid>
      <dc:creator>Deyan</dc:creator>
      <dc:date>2018-08-28T11:36:17Z</dc:date>
    </item>
    <item>
      <title>Re: Account lockout, NIST/ISO/HIPAA etc.</title>
      <link>https://community.isc2.org/t5/Industry-News/Account-lockout-NIST-ISO-HIPAA-etc/m-p/14054#M1517</link>
      <description>&lt;P&gt;I'm on my 3RD Federal agency in 6 years assisting with IAM.&amp;nbsp; They all very.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think the wind is more predictable then most of the CISO's in the government.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Aug 2018 11:40:02 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Account-lockout-NIST-ISO-HIPAA-etc/m-p/14054#M1517</guid>
      <dc:creator>Flyslinger2</dc:creator>
      <dc:date>2018-08-28T11:40:02Z</dc:date>
    </item>
  </channel>
</rss>

