GEN000510 - The system must display a publicly-viewable pattern during a graphical desktop environment session lock.

Information

To protect the on-screen content of a session, it must be replaced with a publicly-viewable pattern upon session lock. Examples of publicly viewable patterns include screen saver patterns, photographic images, solid colors, or a blank screen, so long as none of those patterns convey sensitive information. This requirement applies to graphical desktop environments provided by the system to locally attached displays and input devices, as well as, to graphical desktop environments provided to remote systems using remote access protocols.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Configure the system to display a publicly-viewable pattern during a session lock. This is done graphically by selecting a screensaver theme using gnome-screensaver-preferences command. Any of the themes distributed with RHEL may be used including 'Blank Screen'.

See Also

http://iasecontent.disa.mil/stigs/zip/U_RedHat_5_V1R18_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-14a., CAT|III, CCI|CCI-000061, Group-ID|V-22301, Rule-ID|SV-37222r1_rule, STIG-ID|GEN000510, Vuln-ID|V-22301

Plugin: Unix

Control ID: d2c06e536345701678d63c034c24357b5ddfe87a5437a6e7040882d67fcee05f