8.3.4—Invalid authentication attempts are limited by: Locking out the user ID after not more than 10 attempts.
>Requirement Description
Invalid authentication attempts are limited by: Locking out the user ID after not more than 10 attempts. Setting the lockout duration to a minimum of 30 minutes or until the user’s identity is confirmed. Applicability Notes This requirement is not intended to apply to user accounts on point-of-sale terminals that have access to only one card number at a time to facilitate a single transaction.
>Cross-Framework Mappings
Ask AI
Configure your API key to use AI features.