id: "AC-07(03)" title: "Biometric Attempt Limiting" family: "AC" family_name: "Access Control" sort_id: "ac-07.03" priority: "P1" implementation_level: "organization" parent: "AC-07" enhancement: True
Statement
Limit the number of unsuccessful biometric logon attempts to {{ insert: param, ac-07.03_odp }}.
Guidance
Biometrics are probabilistic in nature. The ability to successfully authenticate can be impacted by many factors, including matching performance and presentation attack detection mechanisms. Organizations select the appropriate number of attempts for users based on organizationally-defined factors.
Assessment Objective
unsuccessful biometric logon attempts are limited to {{ insert: param, ac-07.03_odp }}.
Access control policy
procedures addressing unsuccessful logon attempts on biometric devices
system design documentation
system configuration settings and associated documentation
system audit records
system security plan
other relevant documents or records
System/network administrators
organizational personnel with information security responsibilities
Mechanisms implementing access control policy for unsuccessful logon attempts