Jacob Horne’s Post

View profile for Jacob Horne, graphic

CMMC Town Crier | Ask me about NIST cybersecurity controls | Smashing compliance frameworks for fun and profit | Cyber policy wonk |

New podcast is up: fun with organizationally defined parameters edition Let's take a gander at requirement 3.1.8 in NIST SP 800-171 revision 2. 𝗟𝗶𝗺𝗶𝘁 𝘂𝗻𝘀𝘂𝗰𝗰𝗲𝘀𝘀𝗳𝘂𝗹 𝗹𝗼𝗴𝗼𝗻 𝗮𝘁𝘁𝗲𝗺𝗽𝘁𝘀 That's it. That's all it says. The thing to ask yourself is how would an organization implement such a requirement? What, specifically, would they do? Thankfully, NIST SP 800-171 rev. 3 ditches the riddles and uses the control language found in NIST SP 800-53. The same 3.1.8 requirement now says: a. Enforce a limit of [𝘰𝘳𝘨𝘢𝘯𝘪𝘻𝘢𝘵𝘪𝘰𝘯-𝘥𝘦𝘧𝘪𝘯𝘦𝘥 𝘯𝘶𝘮𝘣𝘦𝘳] consecutive invalid logon attempts by a user during a [𝘰𝘳𝘨𝘢𝘯𝘪𝘻𝘢𝘵𝘪𝘰𝘯-𝘥𝘦𝘧𝘪𝘯𝘦𝘥 𝘵𝘪𝘮𝘦 𝘱𝘦𝘳𝘪𝘰𝘥]. b. When the maximum number of unsuccessful attempts is exceeded, automatically (one or more): - 𝘭𝘰𝘤𝘬 𝘵𝘩𝘦 𝘢𝘤𝘤𝘰𝘶𝘯𝘵 𝘰𝘳 𝘯𝘰𝘥𝘦 𝘶𝘯𝘵𝘪𝘭 𝘳𝘦𝘭𝘦𝘢𝘴𝘦𝘥 𝘣𝘺 𝘢𝘯 𝘢𝘥𝘮𝘪𝘯𝘪𝘴𝘵𝘳𝘢𝘵𝘰𝘳;  - 𝘥𝘦𝘭𝘢𝘺 𝘯𝘦𝘹𝘵 𝘭𝘰𝘨𝘰𝘯 𝘱𝘳𝘰𝘮𝘱𝘵;  - 𝘯𝘰𝘵𝘪𝘧𝘺 𝘴𝘺𝘴𝘵𝘦𝘮 𝘢𝘥𝘮𝘪𝘯𝘪𝘴𝘵𝘳𝘢𝘵𝘰𝘳;  - 𝘵𝘢𝘬𝘦 𝘰𝘵𝘩𝘦𝘳 𝘢𝘤𝘵𝘪𝘰𝘯 Without prescribing specific values, the new 3.1.8 (which is actually the old AC-7 from SP 800-53) provides a framework for limiting unsuccessful logons that is much more clear. We go through several examples in the episode as well as the textbook explanation of ODPs found in NIST guidance. Episode links are in the comments below 👇 Like ❤️ and subscribe 🔔

  • No alternative text description for this image
Heather Noggle

Integrator of Tech and Human Effort | Top Writing Voice | Process and Cybersecurity | Writer | Data Integration | SMB Advocate | Systems Thinker and Innovator | Analogy Queen | Services for Technical Companies

3w

One way to limit them would be to grant access after the 5th unsuccessful attempt. 🤣 - 𝘭𝘰𝘤𝘬 𝘵𝘩𝘦 𝘢𝘤𝘤𝘰𝘶𝘯𝘵 𝘰𝘳 𝘯𝘰𝘥𝘦 𝘶𝘯𝘵𝘪𝘭 𝘳𝘦𝘭𝘦𝘢𝘴𝘦𝘥 𝘣𝘺 𝘢𝘯 𝘢𝘥𝘮𝘪𝘯𝘪𝘴𝘵𝘳𝘢𝘵𝘰𝘳; - 𝘥𝘦𝘭𝘢𝘺 𝘯𝘦𝘹𝘵 𝘭𝘰𝘨𝘰𝘯 𝘱𝘳𝘰𝘮𝘱𝘵; - 𝘯𝘰𝘵𝘪𝘧𝘺 𝘴𝘺𝘴𝘵𝘦𝘮 𝘢𝘥𝘮𝘪𝘯𝘪𝘴𝘵𝘳𝘢𝘵𝘰𝘳; - 𝘵𝘢𝘬𝘦 𝘰𝘵𝘩𝘦𝘳 𝘢𝘤𝘵𝘪𝘰𝘯 So much better. (Though technically my suggestion falls under "take other action.")

Orion Inskip JD, CISSP

Director of Governance, Risk, and Compliance

3w

Are you down with ODP?

See more comments

To view or add a comment, sign in

Explore topics