CCI-000056
Retain the device lock until the user reestablishes access using established identification and authentication procedures.
12 rules found Severity: Medium

Common Access Card (CAC)-based authentication must be enabled and enforced on the Tanium Server for all access and all accounts.
2 rules found Severity: Medium

Multi-factor authentication must be enabled and enforced on the Tanium Server for all access and all accounts.
1 rule found Severity: Medium

2 rules found Severity: Medium

The macOS system must retain the session lock until the user reestablishes access using established identification and authentication procedures.
2 rules found Severity: Medium

The macOS system must initiate the session lock no more than five seconds after a screen saver is started.
2 rules found Severity: Medium

The Ubuntu operating system must retain a users session lock until that user reestablishes access using established identification and authentication procedures.
1 rule found Severity: Medium

The Red Hat Enterprise Linux operating system must enable a user session lock until that user re-establishes access using established identification and authentication procedures.
1 rule found Severity: Medium

The Ubuntu operating system must retain a user's session lock until that user reestablishes access using established identification and authentication procedures.
1 rule found Severity: Medium

AIX must provide the lock command to let users retain their session lock until users are reauthenticated.
1 rule found Severity: Medium

AIX must provide xlock command in the CDE environment to let users retain their sessions lock until users are reauthenticated.
1 rule found Severity: Medium

Windows 11 must be configured to prevent Windows apps from being activated by voice while the system is locked.
1 rule found Severity: Medium

The network device must retain the session lock until the administrator reestablishes access using established identification and authentication procedures.
1 rule found Severity: Medium

The Oracle Linux operating system must enable a user session lock until that user re-establishes access using established identification and authentication procedures.
1 rule found Severity: Medium

Multifactor authentication must be enabled and enforced on the Tanium Server for all access and all accounts.
2 rules found Severity: Medium

TOSS must retain a user's session lock until that user reestablishes access using established identification and authentication procedures.
1 rule found Severity: Medium

NixOS must provide the capability for users to directly initiate a session lock for all connection types.
1 rule found Severity: Medium

2 rules found Severity: Medium

2 rules found Severity: Medium

The ALG providing user access control intermediary services must retain the session lock until the user reestablishes access using established identification and authentication procedures.
1 rule found Severity: Medium

Ubuntu 22.04 LTS must retain a user's session lock until that user reestablishes access using established identification and authentication procedures.
1 rule found Severity: Medium

AlmaLinux OS 9 must be able to directly initiate a session lock for all connection types using smart card when the smart card is removed.
1 rule found Severity: Medium

AlmaLinux OS 9 must prevent a user from overriding the disabling of the graphical user smart card removal action.
1 rule found Severity: Medium

The operating system must retain a users session lock until that user reestablishes access using established identification and authentication procedures.
1 rule found Severity: Medium

IBM z/OS must employ a session manager to manage retaining a users session lock until that user reestablishes access using established identification and authentication procedures.
3 rules found Severity: Medium

The Mainframe Product must retain the session lock until the user reestablishes access using established identification and authentication procedures.
1 rule found Severity: Medium

Windows Server 2019 machine inactivity limit must be set to 15 minutes or less, locking the system with the screen saver.
1 rule found Severity: Medium

Windows 10 must be configured to prevent Windows apps from being activated by voice while the system is locked.
1 rule found Severity: Medium

Windows Server 2022 machine inactivity limit must be set to 15 minutes or less, locking the system with the screen saver.
1 rule found Severity: Medium

OL 8 must enable a user session lock until that user reestablishes access using established identification and authentication procedures for graphical user sessions.
1 rule found Severity: Medium

OL 8 must enable a user session lock until that user re-establishes access using established identification and authentication procedures for command line sessions.
1 rule found Severity: Medium

1 rule found Severity: Medium

OL 8 must enable a user session lock until that user reestablishes access using established identification and authentication procedures for command line sessions.
1 rule found Severity: Medium

OL 8 must be able to initiate directly a session lock for all connection types using smartcard when the smartcard is removed.
1 rule found Severity: Medium

RHEL 8 must enable a user session lock until that user re-establishes access using established identification and authentication procedures for graphical user sessions.
1 rule found Severity: Medium

RHEL 8 must be able to initiate directly a session lock for all connection types using smartcard when the smartcard is removed.
1 rule found Severity: Medium

RHEL 9 must be able to initiate directly a session lock for all connection types using smart card when the smart card is removed.
1 rule found Severity: Medium

RHEL 9 must prevent a user from overriding the disabling of the graphical user smart card removal action.
1 rule found Severity: Medium

RHEL 9 must enable a user session lock until that user re-establishes access using established identification and authentication procedures for graphical user sessions.
1 rule found Severity: Medium

RHEL 9 must prevent a user from overriding the screensaver lock-enabled setting for the graphical user interface.
1 rule found Severity: Medium

2 rules found Severity: Medium

2 rules found Severity: Low

2 rules found Severity: Medium

The VMM must retain the session lock until the user reestablishes access using established identification and authentication procedures.
1 rule found Severity: Medium
