The following sequence of events occurs when an SVN is enabled and a detects a security violation:
The number of invalid attempts that are permitted in a specified time interval is exceeded.
An SVN referral call (with announcements, if assigned) is placed to a designated point, and SVN provides an audit trail that contains information about each attempt to access server that is running Communication Manager.
SVN disables a login ID or remote access following the security violation.
The login ID or remote access remains disabled until someone with an authorized login ID, with the correct permissions reenables it.