Clipping level
A threshold of routine errors or events that is tolerated before an activity is recorded as suspicious or an action is triggered, such as a set number of failed logons before lockout.
A clipping level is a baseline of normal error. Below it, events such as mistyped passwords are treated as ordinary; once the count crosses it, the activity is logged as a violation, an alert is raised or a control responds. The term is mostly found in study sources rather than in current standards. It filters out honest mistakes and sets the point at which a response starts.
The best-known example is the failed logon threshold behind account lockout: a user may mistype a password a few times, but the next failure beyond the clipping level locks the account or introduces a delay. NIST SP 800-53 Rev. 5 control AC-7 leaves that number to the organisation. Clipping levels also appear in audit reduction and in the tuning of an intrusion detection system or a SIEM. Setting the level involves a trade-off: set too low, it floods analysts and locks out legitimate users; set too high, it lets slow or distributed attacks such as password spraying pass unnoticed.
Exam relevance: a scenario is likely to describe a threshold of tolerated errors and ask for its name. Candidates are expected to recognise the clipping level, to connect it with lockout and audit filtering, and to reason about the effect of setting it too low or too high.