5.9 Require a password to wake the computer from sleep or screen saver

Information

Sleep and screensaver modes are low power modes that reduce electrical consumption while the system is not in use.

Rationale:

Prompting for a password when waking from sleep or screensaver mode mitigates the threat of an unauthorized person gaining access to a system in the user's absence.

Impact:

Without a screenlock in place anyone with physical access to the computer would be logged in and able to use the active users session.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Perform the following enable a password for unlock after a screen saver begins:

Open System Preferences

Select Security & Privacy

Select General

Set Require password after or screensaver begins with a time of less than or equal 5 minutes (immediately or 5 seconds is recommended)

Note: The command line check in previous versions of the Benchmark does not work as expected here. The use of a profile is recommended for both implementation and auditing on a 10.13 system.
Issue
https://blog.kolide.com/screensaver-security-on-macos-10-13-is-broken-a385726e2ae2
Profile to control screensaver
https://github.com/rtrouton/profiles/blob/master/SetDefaultScreensaver/SetDefaultScreensaver.mobileconfig

Additional Information:

This only protects the system when the screen saver is running.

See Also

https://workbench.cisecurity.org/files/3197

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5e., CSCv7|4.2

Plugin: Unix

Control ID: db7ff3e5920aa6b49b2cf9d3a5cd22547960600d95a7f732979e0d34a74331aa