AC-9(2)—Previous Logon (Access) Notification
PBMM (P2)
Secret (P2)
Technical
>Control Description
PREVIOUS LOGON NOTIFICATION | SUCCESSFUL / UNSUCCESSFUL LOGONS The information system notifies the user of the number of ☑successful logons/accesses; unsuccessful logon/access attempts; both during ⚙organization-defined time period.
>Tailoring Guidance
Control enhancements (1) and (2) may provide an excessive amount of information to the users at logon which may result in a reduction of its utility as a security mechanisms. Unsuccessful logon attempts should be detected and actioned by the audit function within the organization. Furthermore, control enhancements (1) and (2) are not readily provided by many COTS products and as a result may be difficult to implement.
However, the enhancements are more easily implementable in custom-built software, and web-based applications. Therefore, control enhancements (1) and (2) are recommended for privileged users, but not generally for all organizational users.
Ask AI
Configure your API key to use AI features.