Check: OSX8-00-00010
Apple OSX 10.8 STIG:
OSX8-00-00010
(in version v1 r2)
Title
The operating system must initiate a session lock after the organization-defined time period of inactivity. (Cat II impact)
Discussion
A session time-out lock is a temporary action taken when a user stops work and moves away from the immediate physical vicinity of the system but does not log out because of the temporary nature of the absence. The organization defines the period of inactivity to pass before a session lock is initiated, so this must be configurable.
Check Content
To check if the system has a configuration profile configured to enable the screen saver after a time-out period, run the following command: system_profiler SPConfigurationProfileDataType | grep idleTime | awk '{ print $3 }' | sed 's/;//' The check should return a value of "900" or less, if not, this is a finding.
Fix Text
This setting is enforced using a configuration profile.
Additional Identifiers
Rule ID: SV-65683r1_rule
Vulnerability ID: V-51473
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000057 |
The information system initiates a session lock after the organization-defined time period of inactivity. |
Controls
Number | Title |
---|---|
AC-11 |
Session Lock |