The CA-TSS PTHRESH Control Option must be set to 2.
DISA Rule
SV-223879r1050764_rule
Vulnerability Number
V-223879
Group Title
SRG-OS-000021-GPOS-00005
Rule Version
TSS0-ES-000060
Severity
CAT II
CCI(s)
- CCI-000044 - Enforce the organization-defined limit of consecutive invalid logon attempts by a user during the organization-defined time period.
- CCI-002238 - Automatically lock the account or node for either an organization-defined time period, until the locked account or node is released by an administrator, or delays the next logon prompt according to the organization-defined delay algorithm when the maximum number of unsuccessful logon attempts is exceeded.
Weight
10
Fix Recommendation
Evaluate the impact associated with implementation of the control option. Develop a plan of action to implement the control option setting as specified following and proceed with the change.
PTHRESH(02)
Check Contents
From the ISPF Command Shell enter:
TSS MODIFY STATUS
If the PTHRESH Control Option value is not set to PTHRESH(02), this is a finding.
Vulnerability Number
V-223879
Documentable
False
Rule Version
TSS0-ES-000060
Severity Override Guidance
From the ISPF Command Shell enter:
TSS MODIFY STATUS
If the PTHRESH Control Option value is not set to PTHRESH(02), this is a finding.
Check Content Reference
M
Target Key
4102