STIGQter STIGQter: STIG Summary: Virtual Machine Manager Security Requirements Guide Version: 2 Release: 4 Benchmark Date: 01 Jul 2026:

The VMM must enforce the limit of three consecutive invalid logon attempts by a user during a 15-minute time period.

DISA Rule

SV-207342r958388_rule

Vulnerability Number

V-207342

Group Title

SRG-OS-000021

Rule Version

SRG-OS-000021-VMM-000050

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the VMM to enforce the limit of three consecutive invalid logon attempts by a user during a 15-minute time period, by locking the account.

Check Contents

Verify the VMM enforces the limit of three consecutive invalid logon attempts by a user during a 15-minute time period.

If it does not, this is a finding.

Vulnerability Number

V-207342

Documentable

False

Rule Version

SRG-OS-000021-VMM-000050

Severity Override Guidance

Verify the VMM enforces the limit of three consecutive invalid logon attempts by a user during a 15-minute time period.

If it does not, this is a finding.

Check Content Reference

M

Target Key

2924