Check: WN08-UC-000004
Windows 8/8.1 STIG:
WN08-UC-000004
(in versions v1 r23 through v1 r16)
Title
Changing the screen saver must be prevented. (Cat III impact)
Discussion
Unattended systems are susceptible to unauthorized use and must be locked. Preventing users from changing the screen saver ensures an approved screen saver is used. This protects critical and sensitive data from exposure to unauthorized personnel with physical access to the computer.
Check Content
If the following registry value does not exist or is not configured as specified, this is a finding: Registry Hive: HKEY_CURRENT_USER Subkey: \Software\Microsoft\Windows\CurrentVersion\Policies\System\ Value Name: NoDispScrSavPage Type: REG_DWORD Value: 1
Fix Text
Configure the policy value for User Configuration -> Administrative Templates -> Control Panel -> Personalization -> "Prevent changing screen saver" to "Enabled".
Additional Identifiers
Rule ID: SV-48462r2_rule
Vulnerability ID: V-36775
Group Title: WINUC-000004
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000060 |
Conceal, via the device lock, information previously visible on the display with a publicly viewable image. |
Controls
Number | Title |
---|---|
AC-11(1) |
Pattern-hiding Displays |