NIST 800-53 Rev. 5

AC-7(3): Unsuccessful Logon Attempts | Biometric Attempt Limiting

Control Text:

Limit the number of unsuccessful biometric logon attempts to [Assignment: organization-defined number].

Biometrics are probabilistic in nature. The ability to successfully authenticate can be impacted by many factors, including matching performance and presentation attack detection mechanisms. Organizations select the appropriate number of attempts for users based on organizationally-defined factors.

Related Controls