An organization is implementing a control for the Account Monitoring and Control CIS Control, and have set the Account Lockout Policy as shown below. What is the risk presented by these settings?
Once locked, accounts can't be unlocked? Wow, that's like a one-way ticket to the password graveyard. Guess the IT team will be busy resetting passwords all day.
Password length and complexity reduced? Well, that's one way to make it easier for everyone to remember their passwords. Maybe they should just use '12345' instead.
Okay, so legitimate users might get locked out? Sounds like a great way to keep them from accessing the resources they need. Productivity is overrated anyway.
Dan
1 months agoCarey
1 months agoFelicidad
17 days agoJanessa
1 months agoJesusita
2 months agoBarney
6 days agoCarey
8 days agoUlysses
21 days agoBarrie
2 months agoGail
2 months agoMirta
2 months agoHelene
1 months agoHelene
2 months agoCharlesetta
3 months ago