id: "AC-07(03)" title: "Biometric Attempt Limiting" family: "AC" family_name: "Access Control" sort_id: "ac-07.03" priority: "P1" implementation_level: "organization" parent: "AC-07" enhancement: True


Statement

Limit the number of unsuccessful biometric logon attempts to {{ insert: param, ac-07.03_odp }}.

Guidance

Biometrics are probabilistic in nature. The ability to successfully authenticate can be impacted by many factors, including matching performance and presentation attack detection mechanisms. Organizations select the appropriate number of attempts for users based on organizationally-defined factors.

Assessment Objective

unsuccessful biometric logon attempts are limited to {{ insert: param, ac-07.03_odp }}.

Access control policy

procedures addressing unsuccessful logon attempts on biometric devices

system design documentation

system configuration settings and associated documentation

system audit records

system security plan

other relevant documents or records

System/network administrators

organizational personnel with information security responsibilities

Mechanisms implementing access control policy for unsuccessful logon attempts