1.3 Ensure 'Make pattern visible' is set to Disabled (if using a pattern as device lock mechanism)

Information

Disable pattern visibility if using a pattern as device lock mechanism.

Rationale:

Keeping device unlock pattern visible during device unlock can reveal the pattern and is vulnerable to shoulder surfing attack. Hence, do not make the device unlock pattern visible.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

To disable device unlock pattern visibility, follow the below steps:

* Tap System Settings Gear Icon.
* Scroll to Personal section.
* Tap Security.
* If Screen lock has Pattern underneath the text, follow further steps. If not, then this recommendation is not applicable.
* Tap the Gear Icon in the Screen lock.
* Toggle Make pattern visible to Off position.

Impact:

The user would have to be careful while entering the device unlock pattern since visual feedback would not provide any clues for tracing pattern input.

See Also

https://workbench.cisecurity.org/files/1477

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b.

Plugin: MDM

Control ID: bb495bb55b8a5891a7ad526c4fdf8e239c0c82ffc5b59198d7a5285698ce6cda