A maximum limit on the number and rate of unsuccessful logon attempts should be imposed.
Additional Information:
These limits should provide a margin for user error while protecting the system from persistent attempts at illegitimate access. A record of continuing failure by any particular user to complete successful logon procedures, including password entry and other tests of claimed user identity, may indicate persistent intrusion attempts or lack of fitness for duty. Thus, repeated logon failures might be grounds for denying access to that user. Access might be denied temporarily for some computer- imposed time interval, or indefinitely, pending review by a system administrator. Legitimate users will sometimes have difficulty completing a successful logon, perhaps due to inattention, or a faulty terminal, or faulty communications. Occasional logon failures of that kind should be tolerable to the system, with the user simply invited to try again.