SRS-088 Lock accounts after five failed attempts
Identifier​
SRS-088
Software System​
- Authentication Service
Category​
- Security
Description​
To protect against brute-force and credential-stuffing attacks, the system shall implement an automatic account lockout policy. A user's account shall be locked after five (5) consecutive failed login attempts.
Once an account is locked, any further login attempts for that account shall be denied, even if the credentials are correct. The failed attempt counter shall be reset to zero upon a successful login. The system shall also provide a mechanism for a system administrator to manually unlock a user's account.
The number of attempts before lockout and the duration of the lockout period shall be configurable by an administrator.
Derived from PRS​
PRS-9F2
: Cybersecurity & continuous threat detection