5.17 Disable Fast User Switching

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Fast user switching allows a person to quickly log in to the computer with a different account. While only a minimal security risk, when a second user is logged in, that user might be able to see what processes the first user is using, or possibly gain other information about the first user. In a large directory environment where it is difficult to limit login access many valid users can login to other user's assigned computers.

Rationale:

Fast user switching allows multiple users to run applications simultaneously at console. There can be information disclosed about processes running under a different user. Without a specific configuration to save data and log out users can have unsaved data running in a background session that is not obvious.

Solution

In System Preferences: Accounts, Login Options, make sure the 'Enable fast user switching' checkbox is off.

See Also

https://workbench.cisecurity.org/files/2112

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-10

Plugin: Unix

Control ID: 3b09031e3ddd2fabe961df5d84966aa4b12e76272ceaaff65c8a7748d63e62cf