5.006 - The system will be configured with a password-protected screen saver - ScreenSaveActive

Information

The system should be locked when unattended. Unattended systems are susceptible to unauthorized use. The screen saver should be set at a maximum of 15 minutes and password protected. This protects critical and sensitive data from exposure to unauthorized personnel with physical access to the computer.

Solution

Configure the policy values for User Configuration -> Administrative Templates -> Control Panel -> Personalization -> as follows:

'Enable Screen Saver' will be set to 'Enabled'.
'Password protect the screen saver' will be set to 'Enabled'.
'Screen Saver timeout' will be set to 'Enabled: 900 seconds' (or less).

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Windows_2008_R2_MS_V1R33_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-11, CAT|II, CCI|CCI-000056, CCI|CCI-000057, CCI|CCI-000060, CSCv6|16.5, Rule-ID|SV-32294r1_rule, STIG-ID|5.006, Vuln-ID|V-1122

Plugin: Windows

Control ID: 4b97712eef2b757d7e2af7734739fc01fbc771ab6520c76c6404be8aa17ec353