unified
UC-ACCESS-11 — Defend logons against brute-force and anomalous attempts
Accounts lock or are throttled after a defined number of consecutive failed logon attempts for a set duration or until administrator release. Risk-based signals such as location, device, and behavior trigger adaptive responses including step-up authentication, additional verification, or denial for anomalous logon attempts. Lockout and anomaly events are logged for review.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Access Control & Identity Management
- type
- preventive
- category
- technical
Details
- unified_id
- UC-ACCESS-11
- title
- Defend logons against brute-force and anomalous attempts
- statement
- Accounts lock or are throttled after a defined number of consecutive failed logon attempts for a set duration or until administrator release. Risk-based signals such as location, device, and behavior trigger adaptive responses including step-up authentication, additional verification, or denial for anomalous logon attempts. Lockout and anomaly events are logged for review.
- domain
- Access Control & Identity Management
- control_type
- preventive
- control_category
- technical
- members
- framework
- nist-800-53
- control_id
- AC-7
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- IA-10
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- Authentication Platform & Session Policy Operations operates UC-ACCESS-11 — Defend logons against brute-force and anomalous attempts
- UC-ACCESS-11 — Defend logons against brute-force and anomalous attempts mitigates External fraud — third-party theft, forgery, payment and account fraud
- strength
- primary
- rationale
- Risk-based anomaly signals and lockout directly detect and block credential-stuffing account takeover.
- Security Control Assessment & POA&M Remediation tests UC-ACCESS-11 — Defend logons against brute-force and anomalous attempts
- UC-ACCESS-11 — Defend logons against brute-force and anomalous attempts maps_to AC-7 — Unsuccessful Logon Attempts
- framework
- nist-800-53
- control_id
- AC-7
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Identity Assurance Review oversees UC-ACCESS-11 — Defend logons against brute-force and anomalous attempts
- UC-ACCESS-11 — Defend logons against brute-force and anomalous attempts mitigates Phishing, spear-phishing and social engineering
- strength
- related
- rationale
- Adaptive step-up or denial catches use of phished credentials from anomalous location/device contexts.
- UC-ACCESS-11 — Defend logons against brute-force and anomalous attempts mitigates Weak authentication and password management
- strength
- primary
- rationale
- Account lockout and throttling after consecutive failed attempts directly defeat brute-force login.
- UC-ACCESS-11 — Defend logons against brute-force and anomalous attempts maps_to IA-10 — Adaptive Authentication
- framework
- nist-800-53
- control_id
- IA-10
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.