CCI-000060
Conceal, via the device lock, information previously visible on the display with a publicly viewable image.
1 rule found Severity: Medium

Apple iOS/iPadOS 15 must not display notifications (calendar information) when the device is locked.
1 rule found Severity: Medium

The Lifetime Minutes and Renewal Threshold Minutes Login Session Controls must be set to 10 and 0 respectively in Docker Enterprise.
1 rule found Severity: Medium

Google Android 12 must be configured to not display the following (work profile) notifications when the device is locked: [selection: a. email notifications b. calendar appointments c. contact associated with phone call notification d. text message notification e. other application-based notifications f. all notifications].
2 rules found Severity: Medium

Microsoft Android 11 must be configured to not display the following (work profile) notifications when the device is locked: [selection:- Email notifications - Calendar appointments - Contact associated with phone call notification - Text message notification- Other application-based notifications- All notifications].
1 rule found Severity: Medium

Microsoft Android 11 must be configured to not display the following (work profile) notifications when the device is locked: [selection: - Email notifications - Calendar appointments - Contact associated with phone call notification - Text message notification - Other application-based notifications - All notifications].
1 rule found Severity: Medium

1 rule found Severity: Medium

If TLS optimization is used, the Riverbed Optimization System (RiOS) providing Signed SMB and/or Encrypted MAPI must ensure the integrity and confidentiality of data transmitted over the WAN.
1 rule found Severity: Medium

The Tanium application must retain the session lock until the user reestablishes access using established identification and authentication procedures.
2 rules found Severity: Medium

Multi-factor authentication must be enabled and enforced on the Tanium Server for all access and all accounts.
1 rule found Severity: Medium

2 rules found Severity: Medium

Apple iOS/iPadOS 16 must not display notifications (calendar information) when the device is locked.
2 rules found Severity: Medium

The macOS system must conceal, via the session lock, information previously visible on the display with a publicly viewable image.
1 rule found Severity: Low

The Ubuntu operating system must be configured for users to directly initiate a session lock for all connection types.
1 rule found Severity: Medium

Samsung Android must be configured to not display the following (Work Environment) notifications when the device is locked: all notifications.
2 rules found Severity: Medium

2 rules found Severity: Medium

Apple iOS/iPadOS 17 must not display notifications (calendar information) when the device is locked.
2 rules found Severity: Medium

The macOS system must conceal, via the session lock, information previously visible on the display with a publicly viewable image.
1 rule found Severity: Medium

The Ubuntu operating system must allow users to directly initiate a session lock for all connection types.
1 rule found Severity: Medium

Google Android 14 must be configured to not display the following (work profile) notifications when the device is locked: [selection: a. email notifications b. calendar appointments c. contact associated with phone call notification d. text message notification e. other application-based notifications f. all notifications].
1 rule found Severity: Medium

Google Android 13 must be configured to not display the following (work profile) notifications when the device is locked: [selection: a. email notifications b. calendar appointments c. contact associated with phone call notification d. text message notification e. other application-based notifications f. all notifications].
1 rule found Severity: Medium

AIX CDE must conceal, via the session lock, information previously visible on the display with a publicly viewable image.
1 rule found Severity: Medium

1 rule found Severity: Medium

The network device must conceal, via the session lock, information previously visible on the display with a publicly viewable image.
1 rule found Severity: Medium

Samsung Android must be configured to not display the following (Work Environment) notifications when the device is locked: All notifications.
7 rules found Severity: Medium

Multifactor authentication must be enabled and enforced on the Tanium Server for all access and all accounts.
1 rule found Severity: Medium

TOSS must retain a user's session lock until that user reestablishes access using established identification and authentication procedures.
1 rule found Severity: Medium

NixOS must provide the capability for users to directly initiate a session lock for all connection types.
1 rule found Severity: Medium

1 rule found Severity: Medium

Apple iOS/iPadOS 18 must not display notifications (calendar information) when the device is locked.
1 rule found Severity: Medium

1 rule found Severity: Medium

The ALG providing user access control intermediary services must conceal, via the session lock, information previously visible on the display with a publicly viewable image.
1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

AlmaLinux OS 9 must conceal, via the session lock, information previously visible on the display with a publicly viewable image.
1 rule found Severity: Medium

AlmaLinux OS 9 must prevent a user from overriding the session idle-delay setting for the graphical user interface.
1 rule found Severity: Medium

Google Android 13 must be configured to not display the following (work profile) notifications when the device is locked: [selection: a. email notifications b. calendar appointments c. contact associated with phone call notification d. text message notification e. other application-based notifications f. all notifications].
2 rules found Severity: Medium

Google Android 14 must be configured to not display the following (work profile) notifications when the device is locked: [selection: a. email notifications b. calendar appointments c. contact associated with phone call notification d. text message notification e. other application-based notifications f. all notifications].
2 rules found Severity: Medium

Google Android 15 must be configured to not display the following (work profile) notifications when the device is locked: [selection: a. email notifications b. calendar appointments c. contact associated with phone call notification d. text message notification e. other application-based notifications f. all notifications].
2 rules found Severity: Medium

The operating system must conceal, via the session lock, information previously visible on the display with a publicly viewable image.
1 rule found Severity: Medium

IBM z/OS must employ a session manager that conceal, via the session lock, information previously visible on the display with a publicly viewable image.
1 rule found Severity: Medium

The IBM z/OS must employ a session manager that conceals, via the session lock, information previously visible on the display with a publicly viewable image.
1 rule found Severity: Medium

IBM z/OS must employ a session manager to conceal, via the session lock, information previously visible on the display with a publicly viewable image.
1 rule found Severity: Medium

The Mainframe Product must conceal, via the session lock, information previously visible on the display with a publicly viewable image.
1 rule found Severity: Medium

Windows Server 2019 machine inactivity limit must be set to 15 minutes or less, locking the system with the screen saver.
1 rule found Severity: Medium

Windows Server 2022 machine inactivity limit must be set to 15 minutes or less, locking the system with the screen saver.
1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

OL 8 must prevent a user from overriding the session lock-delay setting for the graphical user interface.
1 rule found Severity: Medium

OL 8 must prevent a user from overriding the session idle-delay setting for the graphical user interface.
1 rule found Severity: Medium

OL 8 must prevent a user from overriding the session lock-enabled setting for the graphical user interface.
1 rule found Severity: Medium

1 rule found Severity: Medium

RHEL 9 must prevent a user from overriding the session idle-delay setting for the graphical user interface.
1 rule found Severity: Medium

RHEL 9 must conceal, via the session lock, information previously visible on the display with a publicly viewable image.
1 rule found Severity: Medium

2 rules found Severity: Medium

2 rules found Severity: Low

The SUSE operating system must conceal, via the session lock, information previously visible on the display with a publicly viewable image in the graphical user interface.
1 rule found Severity: Low

The SUSE operating system must conceal, via the session lock, information previously visible on the display with a publicly viewable image in the graphical user interface (GUI).
1 rule found Severity: Low

The operating system session lock mechanism, when activated on a device with a display screen, must place a publicly viewable pattern onto the associated display, hiding what was previously visible on the screen.
2 rules found Severity: Medium

The VMM must conceal, via the session lock, information previously visible on the display with a publicly viewable image.
1 rule found Severity: Medium

The UEM server must conceal, via the session lock, information previously visible on the display with a publicly viewable image.
1 rule found Severity: Medium

Zebra Android 13 must be configured to not display the following (work profile) notifications when the device is locked: [selection: a. email notifications b. calendar appointments c. contact associated with phone call notification d. text message notification e. other application-based notifications f. all notifications].
2 rules found Severity: Medium
