Compliance Node Overview
MITRE D3FEND D3-AL (Account Locking) is a defensive technique that disables identity accounts after a configured number of failed authentication attempts to defeat brute force, password spray, and credential stuffing. AL counters ATT&CK techniques T1110 (Brute Force), T1078 (Valid Accounts), T1556 (Modify Authentication Process), and T1212 (Exploitation for Credential Access). Required under NIST SP 800-53 AC-7 (Unsuccessful Logon Attempts), PCI DSS v4.0 Req 8.3.4 (lockout after maximum 10 attempts), ISO 27001 A.5.16, HIPAA Security Rule 164.308(a)(5)(ii)(D), and NIST SP 800-63B.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://d3fend.mitre.org/technique/d3f:AccountLocking/
SHA-256 integrity: 1274f4aa4dc3b4b3ed485feb5ea6263cc01ae68988cbe4938f6d01039b506eeb
Primary Citations — 8 traced to source
- MITRE D3FEND Defensive Technique D3-AL: Account Locking (https://d3fend.mitre.org/technique/d3f:AccountLocking/)
- NIST SP 800-53 Rev 5: AC-7 (Unsuccessful Logon Attempts) including AC-7(1)
+ 6 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.