CCI-000057
The information system initiates a session lock after the organization-defined time period of inactivity.
12 rules found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

Apple iOS/iPadOS 15 must be configured to enable a screen-lock policy that will lock the display after a period of inactivity.
1 rule found Severity: Medium

Apple iOS/iPadOS 15 must be configured to lock the display after 15 minutes (or less) of inactivity.
1 rule found Severity: Medium

1 rule found Severity: Medium

The BlackBerry UEM server or platform must be configured to initiate a session lock after a 15-minute period of inactivity.
1 rule found Severity: Medium

1 rule found Severity: Medium

The Lifetime Minutes and Renewal Threshold Minutes Login Session Controls must be set to 10 and 0 respectively in Docker Enterprise.
1 rule found Severity: Medium

Google Android 12 must be configured to enable a screen-lock policy that will lock the display after a period of inactivity.
2 rules found Severity: Medium

2 rules found Severity: Medium

The HYCU 4.1 application and server must initiate a session lock after a 15-minute period of inactivity.
1 rule found Severity: Medium

The Ivanti MobileIron Core server must initiate a session lock after a 15-minute period of inactivity.
1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

The MobileIron Core v10 server or platform must be configured to initiate a session lock after a 15-minute period of inactivity.
1 rule found Severity: Medium

Microsoft Android 11 must be configured to enable a screen-lock policy that will lock the display after a period of inactivity.
2 rules found Severity: Medium

Microsoft Android 11 must be configured to lock the display after 15 minutes (or less) of inactivity.
2 rules found Severity: Medium

Motorola Solutions Android 11 must be configured to enable a screen-lock policy that will lock the display after a period of inactivity.
1 rule found Severity: Medium

Motorola Solutions Android 11 must be configured to lock the display after 15 minutes (or less) of inactivity.
1 rule found Severity: Medium

1 rule found Severity: Medium

11 rules found Severity: Medium

The Samsung SDS EMM or platform must be configured to initiate a session lock after a 15-minute period of inactivity.
1 rule found Severity: Medium

The Tanium Server console must be configured to initiate a session lock after a 15-minute period of inactivity.
1 rule found Severity: Medium

The Tanium Application Server console must be configured to initiate a session lock after a 15-minute period of inactivity.
4 rules found Severity: Medium

The Workspace ONE UEM server or platform must be configured to initiate a session lock after a 15-minute period of inactivity.
1 rule found Severity: Medium

Apple iOS/iPadOS 16 must be configured to enable a screen-lock policy that will lock the display after a period of inactivity.
2 rules found Severity: Medium

Apple iOS/iPadOS 16 must be configured to lock the display after 15 minutes (or less) of inactivity.
2 rules found Severity: Medium

2 rules found Severity: Medium

The Ubuntu operating system must initiate a session lock after a 15-minute period of inactivity for all connection types.
1 rule found Severity: Medium

3 rules found Severity: Medium

The Red Hat Enterprise Linux operating system must initiate a screensaver after a 15-minute period of inactivity for graphical user interfaces.
1 rule found Severity: Medium

The Red Hat Enterprise Linux operating system must prevent a user from overriding the screensaver lock-delay setting for the graphical user interface.
1 rule found Severity: Medium

The Red Hat Enterprise Linux operating system must prevent a user from overriding the session idle-delay setting for the graphical user interface.
1 rule found Severity: Medium

The Red Hat Enterprise Linux operating system must initiate a session lock for the screensaver after a period of inactivity for graphical user interfaces.
1 rule found Severity: Medium

The Red Hat Enterprise Linux operating system must prevent a user from overriding the screensaver idle-activation-enabled setting for the graphical user interface.
1 rule found Severity: Medium

The Red Hat Enterprise Linux operating system must initiate a session lock for graphical user interfaces when the screensaver is activated.
1 rule found Severity: Medium

The Red Hat Enterprise Linux operating system must prevent a user from overriding the screensaver lock-enabled setting for the graphical user interface.
1 rule found Severity: Medium

1 rule found Severity: Medium

Samsung Android must be configured to enable a screen-lock policy that will lock the display after a period of inactivity.
4 rules found Severity: Medium

Zebra Android 11 must be configured to enable a screen-lock policy that will lock the display after a period of inactivity.
1 rule found Severity: Medium

1 rule found Severity: Medium

The BIG-IP appliance must be configured to terminate all management sessions after 10 minutes of inactivity.
1 rule found Severity: High

The BIG-IP Core implementation must terminate all communications sessions at the end of the session or as follows: for in-band management sessions (privileged sessions), the session must be terminated after 10 minutes of inactivity, and for user sessions (nonprivileged sessions), the session must be terminated after 15 minutes of inactivity.
1 rule found Severity: Medium

Apple iOS/iPadOS 17 must be configured to enable a screen-lock policy that will lock the display after a period of inactivity.
1 rule found Severity: Medium

Apple iOS/iPadOS 17 must be configured to lock the display after 15 minutes (or less) of inactivity.
2 rules found Severity: Medium

The Ubuntu operating system must retain a user's session lock until that user reestablishes access using established identification and authentication procedures.
1 rule found Severity: Medium

The Ubuntu operating system must allow users to directly initiate a session lock for all connection types.
1 rule found Severity: Medium

The F5 BIG-IP appliance must set the idle time before automatic logout to five minutes of inactivity except to fulfill documented and validated mission requirements.
1 rule found Severity: High

Google Android 14 must be configured to enable a screen-lock policy that will lock the display after a period of inactivity.
1 rule found Severity: Medium

3 rules found Severity: Medium

Google Android 13 must be configured to enable a screen-lock policy that will lock the display after a period of inactivity.
3 rules found Severity: Medium

3 rules found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

The terminal or workstation must lock out after a maximum of 15 minutes of inactivity, requiring the account password to resume.
1 rule found Severity: Medium

AIX must automatically lock after 15 minutes of inactivity in the CDE Graphical desktop environment.
1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

The Jamf Pro EMM server or platform must be configured to initiate a session lock after a 15-minute period of inactivity.
1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

The network device must be configured to enable network administrators to directly initiate a session lock.
1 rule found Severity: Medium

The Oracle Linux operating system must enable a user session lock until that user re-establishes access using established identification and authentication procedures.
1 rule found Severity: Medium

The Oracle Linux operating system must prevent a user from overriding the screensaver lock-enabled setting for the graphical user interface.
1 rule found Severity: Medium

The Oracle Linux operating system must initiate a screensaver after a 15-minute period of inactivity for graphical user interfaces.
1 rule found Severity: Medium

The Oracle Linux operating system must prevent a user from overriding the screensaver lock-delay setting for the graphical user interface.
1 rule found Severity: Medium

The Oracle Linux operating system must prevent a user from overriding the session idle-delay setting for the graphical user interface.
1 rule found Severity: Medium

The Oracle Linux operating system must initiate a session lock for the screensaver after a period of inactivity for graphical user interfaces.
1 rule found Severity: Medium

The Oracle Linux operating system must prevent a user from overriding the screensaver idle-activation-enabled setting for the graphical user interface.
1 rule found Severity: Medium

The Oracle Linux operating system must initiate a session lock for graphical user interfaces when the screensaver is activated.
1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

Multifactor authentication must be enabled and enforced on the Tanium Server for all access and all accounts.
1 rule found Severity: Medium

TOSS must retain a user's session lock until that user reestablishes access using established identification and authentication procedures.
1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

NixOS must provide the capability for users to directly initiate a session lock for all connection types.
1 rule found Severity: Medium

2 rules found Severity: Medium

Apple iOS/iPadOS 18 must be configured to lock the display after 15 minutes (or less) of inactivity.
1 rule found Severity: Medium

1 rule found Severity: Medium

The ALG providing user access control intermediary services must initiate a session lock after a 15-minute period of inactivity.
1 rule found Severity: Medium

The ALG providing user access control intermediary services must provide the capability for users to directly initiate a session lock.
1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

AlmaLinux OS 9 must initiate a session lock for graphical user interfaces when the screensaver is activated.
1 rule found Severity: Medium

AlmaLinux OS 9 must prevent a user from overriding the session lock-delay setting for the graphical user interface.
1 rule found Severity: Medium

AlmaLinux OS 9 must automatically exit interactive command shell user sessions after 10 minutes of inactivity.
1 rule found Severity: Medium

2 rules found Severity: Medium

The operating system must initiate a session lock after a 15-minute period of inactivity for all connection types.
1 rule found Severity: Medium

The operating system must provide the capability for users to directly initiate a session lock for all connection types.
1 rule found Severity: Medium

The Remote Access VPN Gateway must terminate remote access network connections after an organization-defined time period.
2 rules found Severity: Medium

IBM z/OS must employ a session manager to manage session lock after a 15-minute period of inactivity.
2 rules found Severity: Medium

IBM z/OS must employ a session manager configured for users to directly initiate a session lock for all connection types.
1 rule found Severity: Medium

IBM z/OS must employ a session for users to directly initiate a session lock for all connection types.
1 rule found Severity: Medium

IBM z/OS must employ a session manager for users to directly initiate a session lock for all connection types.
1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

SharePoint must support the requirement to initiate a session lock after 15 minutes of system or application inactivity has transpired.
1 rule found Severity: Medium

Windows Server 2019 machine inactivity limit must be set to 15 minutes or less, locking the system with the screen saver.
1 rule found Severity: Medium

1 rule found Severity: Medium

Windows Server 2022 machine inactivity limit must be set to 15 minutes or less, locking the system with the screen saver.
1 rule found Severity: Medium

OL 8 must enable a user session lock until that user reestablishes access using established identification and authentication procedures for graphical user sessions.
1 rule found Severity: Medium

1 rule found Severity: Medium

OL 8 must enable a user session lock until that user re-establishes access using established identification and authentication procedures for command line sessions.
1 rule found Severity: Medium

1 rule found Severity: Medium

OL 8 must enable a user session lock until that user reestablishes access using established identification and authentication procedures for command line sessions.
1 rule found Severity: Medium

OL 8 must be able to initiate directly a session lock for all connection types using smartcard when the smartcard is removed.
1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

OL 8 must prevent a user from overriding the session lock-delay setting for the graphical user interface.
1 rule found Severity: Medium

OL 8 must prevent a user from overriding the session idle-delay setting for the graphical user interface.
1 rule found Severity: Medium

OL 8 must prevent a user from overriding the session lock-enabled setting for the graphical user interface.
1 rule found Severity: Medium

1 rule found Severity: Medium

RHEL 8 must prevent a user from overriding the session lock-delay setting for the graphical user interface.
1 rule found Severity: Medium

RHEL 8 must initiate a session lock for graphical user interfaces when the screensaver is activated.
1 rule found Severity: Medium

RHEL 8 must prevent a user from overriding the session idle-delay setting for the graphical user interface.
1 rule found Severity: Medium

RHEL 8 must prevent a user from overriding the screensaver lock-enabled setting for the graphical user interface.
1 rule found Severity: Medium

RHEL 9 must be able to initiate directly a session lock for all connection types using smart card when the smart card is removed.
1 rule found Severity: Medium

RHEL 9 must prevent a user from overriding the disabling of the graphical user smart card removal action.
1 rule found Severity: Medium

RHEL 9 must enable a user session lock until that user re-establishes access using established identification and authentication procedures for graphical user sessions.
1 rule found Severity: Medium

RHEL 9 must prevent a user from overriding the screensaver lock-enabled setting for the graphical user interface.
1 rule found Severity: Medium

1 rule found Severity: Medium

RHEL 9 must prevent a user from overriding the session idle-delay setting for the graphical user interface.
1 rule found Severity: Medium

RHEL 9 must initiate a session lock for graphical user interfaces when the screensaver is activated.
1 rule found Severity: Medium

RHEL 9 must prevent a user from overriding the session lock-delay setting for the graphical user interface.
1 rule found Severity: Medium

RHEL 9 must automatically exit interactive command shell user sessions after 15 minutes of inactivity.
1 rule found Severity: Medium

2 rules found Severity: Medium

2 rules found Severity: Low

The SUSE operating system must initiate a session lock after a 15-minute period of inactivity for the graphical user interface.
1 rule found Severity: Medium

2 rules found Severity: Medium

The SUSE operating system must initiate a session lock after a 15-minute period of inactivity for the graphical user interface (GUI).
1 rule found Severity: Medium

Graphical desktop environments provided by the system must automatically lock after 15 minutes of inactivity.
2 rules found Severity: Medium

The operating system must provide the capability for users to directly initiate session lock mechanisms.
2 rules found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

2 rules found Severity: Medium

1 rule found Severity: Medium

2 rules found Severity: Medium

2 rules found Severity: Medium
