Capacity
CCI-000060
Conceal, via the device lock, information previously visible on the display with a publicly viewable image.
Choose one
13
Rule
Severity: Medium
Set GNOME3 Screensaver Inactivity Timeout
12
Rule
Severity: Medium
Set GNOME3 Screensaver Lock Delay After Activation Period
15
Rule
Severity: Medium
Enable GNOME3 Screensaver Lock After Idle Period
13
Rule
Severity: Medium
Implement Blank Screensaver
11
Rule
Severity: Medium
Ensure Users Cannot Change GNOME3 Screensaver Settings
13
Rule
Severity: Medium
Ensure Users Cannot Change GNOME3 Session Idle Settings
8
Rule
Severity: Medium
Configure tmux to lock session after inactivity
4
Rule
Severity: Medium
Check that vlock is installed to allow session locking
1
Rule
Severity: Medium
Apple iOS/iPadOS 15 must be configured to not display notifications when the device is locked.
1
Rule
Severity: Medium
Apple iOS/iPadOS 15 must not display notifications (calendar information) when the device is locked.
2
Rule
Severity: Medium
The ALG providing user access control intermediary services must conceal, via the session lock, information previously visible on the display with a publicly viewable image.
1
Rule
Severity: Medium
The Lifetime Minutes and Renewal Threshold Minutes Login Session Controls must be set to 10 and 0 respectively in Docker Enterprise.
2
Rule
Severity: Medium
Google Android 12 must be configured to not display the following (work profile) notifications when the device is locked: [selection:
a. email notifications
b. calendar appointments
c. contact associated with phone call notification
d. text message notification
e. other application-based notifications
f. all notifications].
4
Rule
Severity: Medium
Google Android 13 must be configured to not display the following (work profile) notifications when the device is locked: [selection:
a. email notifications
b. calendar appointments
c. contact associated with phone call notification
d. text message notification
e. other application-based notifications
f. all notifications].
2
Rule
Severity: Medium
The Mainframe Product must conceal, via the session lock, information previously visible on the display with a publicly viewable image.
1
Rule
Severity: Medium
Microsoft Android 11 must be configured to not display the following (work profile) notifications when the device is locked: [selection:- Email notifications - Calendar appointments - Contact associated with phone call notification - Text message notification- Other application-based notifications- All notifications].
1
Rule
Severity: Medium
Microsoft Android 11 must be configured to not display the following (work profile) notifications when the device is locked: [selection:
- Email notifications
- Calendar appointments
- Contact associated with phone call notification
- Text message notification
- Other application-based notifications
- All notifications].
1
Rule
Severity: Medium
Nutanix AOS must disconnect a session after 15 minutes of idle time for all connection types.
1
Rule
Severity: Medium
If TLS optimization is used, the Riverbed Optimization System (RiOS) providing Signed SMB and/or Encrypted MAPI must ensure the integrity and confidentiality of data transmitted over the WAN.
9
Rule
Severity: Medium
Samsung Android must be configured to not display the following (Work Environment) notifications when the device is locked: All notifications.
3
Rule
Severity: Medium
The Tanium application must retain the session lock until the user reestablishes access using established identification and authentication procedures.
1
Rule
Severity: Medium
Multi-factor authentication must be enabled and enforced on the Tanium Server for all access and all accounts.
2
Rule
Severity: Medium
The UEM server must conceal, via the session lock, information previously visible on the display with a publicly viewable image.
3
Rule
Severity: Medium
Apple iOS/iPadOS 16 must be configured to not display notifications when the device is locked.
3
Rule
Severity: Medium
Apple iOS/iPadOS 16 must not display notifications (calendar information) when the device is locked.
3
Rule
Severity: Medium
Apple iOS/iPadOS 17 must be configured to not display notifications when the device is locked.
3
Rule
Severity: Medium
Apple iOS/iPadOS 17 must not display notifications (calendar information) when the device is locked.
1
Rule
Severity: Low
The macOS system must conceal, via the session lock, information previously visible on the display with a publicly viewable image.
4
Rule
Severity: Medium
The macOS system must be configured to disable hot corners.
3
Rule
Severity: Medium
The macOS system must conceal, via the session lock, information previously visible on the display with a publicly viewable image.
3
Rule
Severity: Medium
The macOS system must disable hot corners.
1
Rule
Severity: Medium
The Ubuntu operating system must be configured for users to directly initiate a session lock for all connection types.
2
Rule
Severity: Medium
The Ubuntu operating system must allow users to directly initiate a session lock for all connection types.
2
Rule
Severity: Medium
Google Android 13 must be configured to not display the following (work profile) notifications when the device is locked: [selection:
a. email notifications
b. calendar appointments
c. contact associated with phone call notification
d. text message notification
e. other application-based notifications
f. all notifications].
4
Rule
Severity: Medium
Google Android 14 must be configured to not display the following (work profile) notifications when the device is locked: [selection:
a. email notifications
b. calendar appointments
c. contact associated with phone call notification
d. text message notification
e. other application-based notifications
f. all notifications].
2
Rule
Severity: Medium
The operating system must conceal, via the session lock, information previously visible on the display with a publicly viewable image.
2
Rule
Severity: Medium
AIX CDE must conceal, via the session lock, information previously visible on the display with a publicly viewable image.
2
Rule
Severity: Medium
IBM z/OS must employ a session manager that conceal, via the session lock, information previously visible on the display with a publicly viewable image.
2
Rule
Severity: Medium
IBM z/OS must employ a session manager to conceal, via the session lock, information previously visible on the display with a publicly viewable image.
2
Rule
Severity: Medium
The IBM z/OS must employ a session manager that conceals, via the session lock, information previously visible on the display with a publicly viewable image.
2
Rule
Severity: Medium
Windows Ink Workspace must be configured to disallow access above the lock.
2
Rule
Severity: Medium
Windows Server 2019 machine inactivity limit must be set to 15 minutes or less, locking the system with the screen saver.
2
Rule
Severity: Medium
Windows Server 2022 machine inactivity limit must be set to 15 minutes or less, locking the system with the screen saver.
2
Rule
Severity: Medium
OL 8 must initiate a session lock for graphical user interfaces when the screensaver is activated.
2
Rule
Severity: Medium
OL 8 must automatically lock graphical user sessions after 15 minutes of inactivity.
2
Rule
Severity: Medium
OL 8 must automatically lock command line user sessions after 15 minutes of inactivity.
2
Rule
Severity: Medium
OL 8 must prevent a user from overriding the session lock-delay setting for the graphical user interface.
2
Rule
Severity: Medium
OL 8 must prevent a user from overriding the session idle-delay setting for the graphical user interface.
2
Rule
Severity: Medium
OL 8 must prevent a user from overriding the session lock-enabled setting for the graphical user interface.
4
Rule
Severity: Medium
The SUSE operating system must be able to lock the graphical user interface (GUI).
4
Rule
Severity: Low
The SUSE operating system must utilize vlock to allow for session locking.
2
Rule
Severity: Low
The SUSE operating system must conceal, via the session lock, information previously visible on the display with a publicly viewable image in the graphical user interface.
2
Rule
Severity: Medium
RHEL 9 must automatically lock graphical user sessions after 15 minutes of inactivity.
2
Rule
Severity: Medium
RHEL 9 must prevent a user from overriding the session idle-delay setting for the graphical user interface.
2
Rule
Severity: Medium
RHEL 9 must conceal, via the session lock, information previously visible on the display with a publicly viewable image.
2
Rule
Severity: Low
The SUSE operating system must conceal, via the session lock, information previously visible on the display with a publicly viewable image in the graphical user interface (GUI).
1
Rule
Severity: Medium
RHEL 9 must ensure session control is automatically started at shell initialization.
1
Rule
Severity: Medium
RHEL 9 must automatically lock command line user sessions after 15 minutes of inactivity.
4
Rule
Severity: Medium
The operating system session lock mechanism, when activated on a device with a display screen, must place a publicly viewable pattern onto the associated display, hiding what was previously visible on the screen.
2
Rule
Severity: Medium
Samsung Android must be configured to not display the following (Work Environment) notifications when the device is locked: all notifications.
2
Rule
Severity: Medium
The VMM must conceal, via the session lock, information previously visible on the display with a publicly viewable image.
1
Rule
Severity: Medium
The macOS system must prevent AdminHostInfo from being available at LoginWindow.
1
Rule
Severity: Medium
Ubuntu 22.04 LTS must allow users to directly initiate a session lock for all connection types.
1
Rule
Severity: Medium
Dragos must configure idle timeouts at 10 minutes.
1
Rule
Severity: Medium
Google Android 14 must be configured to not display the following (work profile) notifications when the device is locked: [selection:
a. email notifications
b. calendar appointments
c. contact associated with phone call notification
d. text message notification
e. other application-based notifications
f. all notifications].
2
Rule
Severity: Medium
Google Android 15 must be configured to not display the following (work profile) notifications when the device is locked: [selection:
a. email notifications
b. calendar appointments
c. contact associated with phone call notification
d. text message notification
e. other application-based notifications
f. all notifications].
1
Rule
Severity: Medium
The network device must conceal, via the session lock, information previously visible on the display with a publicly viewable image.
1
Rule
Severity: Medium
SLEM 5 must use vlock to allow for session locking.
1
Rule
Severity: Medium
Multifactor authentication must be enabled and enforced on the Tanium Server for all access and all accounts.
1
Rule
Severity: Medium
TOSS must retain a user's session lock until that user reestablishes access using established identification and authentication procedures.
1
Rule
Severity: Medium
Apple iOS/iPadOS 18 must be configured to not display notifications when the device is locked.
1
Rule
Severity: Medium
Apple iOS/iPadOS 18 must not display notifications (calendar information) when the device is locked.
Patternfly
PatternFly elements
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.
Modules
66%