2.3.4 Set a screen corner to Start Screen Saver

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Ensuring the user has a quick method to lock their screen may reduce opportunity for individuals in close physical proximity of the device to see screen contents.

Solution

In System Preferences: Desktop & Screen Saver: Screen Saver: Hot Corners, make sure at least one Active Screen Corner is set to Start Screen Saver.
Make sure the user knows about this feature. The screen corners can be set using the defaults command, but the permutations of combinations are many.
The plist file to check is ~/Library/Preferences/com.apple.dock and the keys are:
wvous-bl-corner
wvous-br-corner
wvous-tl-corner
wvous-tr-corner
There are also modifier keys to check and various values for each of these keys. A value of 5 means the corner will start the screen saver.
The corresponding wvous-xx-modifier key should be set to 0.

See Also

https://benchmarks.cisecurity.org/tools2/osx/CIS_Apple_OSX_10.11_Benchmark_v1.0.0.pdf

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-11

Plugin: Unix

Control ID: 5418f37b96e57c280835d45069ae17ef35f12b2ae1856733847e4c5516a3c75d