Skip to content

The Smart Card removal option must be configured to Force Logoff or Lock Workstation.

An XCCDF Rule

Description

Unattended systems are susceptible to unauthorized use and must be locked. Configuring a system to lock when a smart card is removed will ensure the system is inaccessible when unattended.

ID
SV-253448r991589_rule
Version
WN11-SO-000095
Severity
Medium
References
Updated

Remediation Templates

A Manual Procedure

Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> "Interactive logon: Smart card removal behavior" to "Lock Workstation" or "Force Logoff".