AOSX-11-000020 - The system must retain the session lock until the user reestablishes access using established ident and auth procedures.

Information

Users must be prompted to enter their passwords when unlocking the screensaver. The screensaver acts as a session lock and prevents unauthorized users from accessing the current user's account.

Solution

This setting is enforced using the "Login Window Policy" configuration profile.

See Also

https://iasecontent.disa.mil/stigs/zip/U_Apple_OS_X_10-11_V1R6_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-11, CAT|II, CCI|CCI-000056, CSCv6|16.5, Rule-ID|SV-81955r1_rule, STIG-ID|AOSX-11-000020, Vuln-ID|V-67465

Plugin: Unix

Control ID: c8178958243bf8fcd9e3202f1b031f655b59b1da3f0a1132887a0ad412794e1c