| 1.2.6 - /etc/security/user - 'loginretries <= 3' | CIS AIX 5.3/6.1 L1 v1.1.0 | Unix | ACCESS CONTROL |
| 1.3 CISC-ND-000150 | CIS Cisco IOS XR Router NDM STIG v1.0.0 CAT II | Cisco | ACCESS CONTROL |
| 1.7 CISC-ND-000150 | CIS Cisco NX OS Switch NDM STIG v1.1.0 CAT II | Cisco | ACCESS CONTROL |
| 1.44 ALMA-09-007500 | CIS Cloud Linux AlmaLinux OS 9 STIG v1.0.0 CAT II | Unix | ACCESS CONTROL |
| 1.45 ALMA-09-007610 | CIS Cloud Linux AlmaLinux OS 9 STIG v1.0.0 CAT II | Unix | ACCESS CONTROL |
| 1.46 ALMA-09-007720 | CIS Cloud Linux AlmaLinux OS 9 STIG v1.0.0 CAT II | Unix | ACCESS CONTROL |
| 1.46 WN10-AC-000010 | CIS Microsoft Windows 10 STIG v1.0.0 CAT II | Windows | ACCESS CONTROL |
| 1.47 ALMA-09-007940 | CIS Cloud Linux AlmaLinux OS 9 STIG v1.0.0 CAT II | Unix | ACCESS CONTROL |
| 1.48 ALMA-09-007830 | CIS Cloud Linux AlmaLinux OS 9 STIG v1.0.0 CAT II | Unix | ACCESS CONTROL |
| 1.49 WN16-AC-000020 | CIS Microsoft Windows Server 2016 STIG v4.0.0 DC CAT II | Windows | ACCESS CONTROL |
| 1.49 WN16-AC-000020 | CIS Microsoft Windows Server 2016 STIG v4.0.0 MS CAT II | Windows | ACCESS CONTROL |
| 1.49 WN19-AC-000020 | CIS Microsoft Windows Server 2019 STIG v4.0.0 MS CAT II | Windows | ACCESS CONTROL |
| 1.49 WN19-AC-000020 | CIS Microsoft Windows Server 2019 STIG v4.0.0 DC CAT II | Windows | ACCESS CONTROL |
| 1.49 WN22-AC-000020 | CIS Microsoft Windows Server 2022 STIG v3.0.0 DC CAT II | Windows | ACCESS CONTROL |
| 1.62 PHTN-40-000196 | CIS VMware vSphere 8.0 vCenter Appliance Photon OS 4.0 STIG v1.0.0 CAT II | Unix | ACCESS CONTROL |
| 1.85 SOL-11.1-040140 | CIS Solaris 11 SPARC STIG v1.0.0 CAT II | Unix | ACCESS CONTROL |
| 1.154 AZLX-23-002420 | CIS Amazon Linux 2023 STIG v1.0.0 CAT II | Unix | ACCESS CONTROL |
| 1.281 RHEL-10-600600 | CIS Red Hat Enterprise Linux 10 STIG v1.0.0 CAT II | Unix | ACCESS CONTROL |
| 1.285 RHEL-09-411105 | CIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II | Unix | ACCESS CONTROL |
| 1.397 OL09-00-003010 | CIS Oracle Linux 9 STIG v1.0.0 CAT II | Unix | ACCESS CONTROL |
| 1.398 OL09-00-003011 | CIS Oracle Linux 9 STIG v1.0.0 CAT II | Unix | ACCESS CONTROL |
| 1.399 OL09-00-003012 | CIS Oracle Linux 9 STIG v1.0.0 CAT II | Unix | ACCESS CONTROL |
| 1.402 OL09-00-003022 | CIS Oracle Linux 9 STIG v1.0.0 CAT II | Unix | ACCESS CONTROL |
| 1.403 OL09-00-003023 | CIS Oracle Linux 9 STIG v1.0.0 CAT II | Unix | ACCESS CONTROL |
| 4.002 - Number of allowed bad-logon attempts does not meet minimum requirements. | DISA Windows Vista STIG v6r41 | Windows | ACCESS CONTROL |
| 4.34 init.ora - 'sec_max_failed_login_attempts = 3' | CIS v1.1.0 Oracle 11g OS L1 | Unix | ACCESS CONTROL |
| 4.34 init.ora - 'sec_max_failed_login_attempts = 3' | CIS v1.1.0 Oracle 11g OS Windows Level 1 | Windows | ACCESS CONTROL |
| 5.3.3.1.12 Ensure silent is set on the pam_faillock module | CIS Red Hat Enterprise Linux 8 STIG v2.0.0 STIG | Unix | ACCESS CONTROL |
| 5.3.3.1.13 Ensure silent is set in /etc/security/faillock.conf | CIS Red Hat Enterprise Linux 8 STIG v2.0.0 STIG | Unix | ACCESS CONTROL |
| 7.12 Limit number of failed login attempts | CIS Solaris 9 v1.3 | Unix | ACCESS CONTROL |
| AIOS-14-000400 - The mobile operating system must be configured to not allow more than ten consecutive failed authentication attempts. | MobileIron - DISA Apple iOS/iPadOS 14 v1r3 | MDM | ACCESS CONTROL |
| AIOS-16-706900 - Apple iOS/iPadOS 16 must be configured to not allow more than 10 consecutive failed authentication attempts. | MobileIron - DISA Apple iOS/iPadOS BYOAD 16 v1r2 | MDM | ACCESS CONTROL |
| AIOS-17-706900 - Apple iOS/iPadOS 17 must be configured to not allow more than 10 consecutive failed authentication attempts. | MobileIron - DISA Apple iOS/iPadOS BYOAD 17 v1r2 | MDM | ACCESS CONTROL |
| AIOS-26-006900 - Apple iOS/iPadOS 26 must be configured to not allow more than 10 consecutive failed authentication attempts. | AirWatch - DISA Apple iOS/iPadOS 26 v1r3 | MDM | ACCESS CONTROL |
| ESXi: esxi-8.account-lockout | VMware vSphere Security Configuration and Hardening Guide | VMware | ACCESS CONTROL |
| EX19-ED-000019 - Exchange external Receive connectors must be domain secure-enabled. | DISA Microsoft Exchange 2019 Edge Server STIG v2r2 | Windows | ACCESS CONTROL |
| GOOG-12-006400 - Google Android 12 must be configured to not allow more than 10 consecutive failed authentication attempts. | MobileIron - DISA Google Android 12 COPE v1r2 | MDM | ACCESS CONTROL |
| GOOG-13-006400 - Google Android 13 must be configured to not allow more than 10 consecutive failed authentication attempts. | AirWatch - DISA Google Android 13 COBO STIG v2r3 | MDM | ACCESS CONTROL |
| GOOG-13-006400 - Google Android 13 must be configured to not allow more than 10 consecutive failed authentication attempts. | MobileIron - DISA Google Android 13 COPE STIG v2r3 | MDM | ACCESS CONTROL |
| GOOG-14-006400 - Google Android 14 must be configured to not allow more than 10 consecutive failed authentication attempts. | AirWatch - DISA Google Android 14 COPE STIG v2r5 | MDM | ACCESS CONTROL |
| GOOG-14-706400 - Google Android 14 must be configured to not allow more than 10 consecutive failed authentication attempts. | AirWatch - DISA Google Android 14 BYOAD v1r2 | MDM | ACCESS CONTROL |
| GOOG-15-006400 - Google Android 15 must be configured to not allow more than 10 consecutive failed authentication attempts. | AirWatch - DISA Google Android 15 COPE STIG v1r5 | MDM | ACCESS CONTROL |
| GOOG-16-006400 - Google Android 16 must be configured to not allow more than 10 consecutive failed authentication attempts. | MobileIron - DISA Google Android 16 COPE STIG v1r3 | MDM | ACCESS CONTROL |
| HP ProCurve - 'Configure login attempts' | TNS HP ProCurve | HPProCurve | ACCESS CONTROL |
| Huawei: SSH Max Retries <= 3 | TNS Huawei VRP Best Practice Audit | Huawei | ACCESS CONTROL |
| Lockout for failed password attempts - 'auth [default=die] pam_faillock.so authfail audit deny=5 unlock_time=900' | Tenable Cisco Firepower Management Center OS Best Practices Audit | Unix | ACCESS CONTROL |
| Lockout for failed password attempts - 'auth required pam_faillock.so preauth audit silent deny=5 unlock_time=900' | Tenable Cisco Firepower Management Center OS Best Practices Audit | Unix | ACCESS CONTROL |
| Lockout for failed password attempts - 'auth sufficient pam_unix.so' | Tenable Cisco Firepower Management Center OS Best Practices Audit | Unix | ACCESS CONTROL |
| vCenter: vcenter-8.administration-sso-lockout-policy-max-attempts | VMware vSphere Security Configuration and Hardening Guide | VMware | ACCESS CONTROL |
| ZEBR-14-006400 - Zebra Android 14 must be configured to not allow more than 10 consecutive failed authentication attempts. | AirWatch - DISA Zebra Android 14 COBO STIG v1r2 | MDM | ACCESS CONTROL |