The time, date, ip address for the last login should be stored for each user.
Total successful / unsuccessful login attempts should also be logged. After x number of unsuccessful login attempts, a user's account should be automatically disabled.
Log in to post a comment.