If the system does not recognize the authentication credentials when entered, an explanatory message must be displayed to the account holder that prompts the account holder to try again. The error message must be the same regardless of which authentication credential is incorrect.
The system must support a mechanism that locks an account in the event that suspicious activity is detected, such as three. consecutive, failed access attempts in a 30-minute period. A multi-factor authentication process must be employed for the account to be unlocked.
S.D. Admin. R. 20:18:36.13
General Authority: SDCL 42-7B-7, 42-7B-11(13).
Law Implemented: SDCL 42-7B-77.