Diff: FAQ #1072

What is the purpose of requiring account lockout, per PCI DSS requirement 8.5.14?

Earlier Version
Later Version
Removed
Added
The intent of this requirement is to prevent an unauthorized person from using an unattended console/PC to gain access to the user’s computer and accounts, and potentially to the company’s network.

This does not prevent legitimate activities from being performed while the console/PC is unattended. For example, if a user needs to run a program from an unattended computer, they can login to the computer to initiate the program, and then ?lock? the computer so that no one else can use their login while the computer is unattended. An example of how to meet this requirement includes configuring an automated screensaver to launch whenever the console has been idle for 15 minutes, and requires the logged-in user to enter their password in order to unlock the screen.

Note: For critical systems (for example, systems that perform security functions or have access to sensitive data), it may be appropriate to reduce the time that the system is idle before the console is locked.

(Note:
PCI DSS requirement 8.5.14 is to lock out accounts due to suspicious activity, to prevent a malicious user from gaining access to users’ accounts, by continually trying to guess a user?s password over and over. The lockout occurs after six consecutive failed login attempts, and remains in place for at least 30 minutes or until reset by the administrator.Requirement numbers refer to PCI DSS version 3)

Disclaimer: This FAQ has been processed for display on this website and may contain errors. Please check the original FAQ on the PCI SSC website for the authoritative version.