ℹ️
Reference Content: This is a copy of content from the PCI Security Standards Council FAQ database, preserved for tracking changes over time.
View Original →
FAQ #1072 Published

What is the purpose of requiring account lockout, per PCI DSS requirement 8.5.14?

The intent of PCI DSS requirement 8.5.14 is to lock out accounts due to suspicious activity, to prevent a malicious user from gaining access to users’ accounts, by continually trying to guess a user?s password over and over. The lockout occurs after six consecutive failed login attempts, and remains in place for at least 30 minutes or until reset by the administrator.

Disclaimer: This FAQ has been processed for display on this website and may contain errors. Please check the original FAQ on the PCI SSC website for the authoritative version.