5.4.5 Ensure default user shell timeout is 900 seconds or less - /etc/profile

Information

The default TMOUT determines the shell timeout for users. The TMOUT value is measured in seconds.

Rationale:

Having no timeout value associated with a shell could allow an unauthorized user access to another user's shell session (e.g. user walks away from their computer and doesn't lock the screen). Setting a timeout value at least reduces the risk of this happening.

Solution

Edit the /etc/bashrc and /etc/profile files (and the appropriate files for any other shell supported on your system) and add or edit any umask parameters as follows:

TMOUT=600

See Also

https://workbench.cisecurity.org/files/2449

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-11, CSCv7|16.11

Plugin: Unix

Control ID: 357048bbc0f3d6cbdb3ed94adae7ec9629dcecc81f8dda376600a721cf014833