SOL-11.1-040180 - Graphical desktop environments provided by the system must automatically lock after 15 minutes of inactivity.

Information

Allowing access to a graphical environment when the user is not attending the system can allow unauthorized users access to the system.

Solution

The root role is required.

Edit the global screensaver configuration file to ensure 15 minute screen lock.

# pfedit /usr/share/X11/app-defaults/XScreenSaver

Find the timeout control lines and change them to read:

*timeout: 0:15:00
*lockTimeout:0:00:05
*lock: True

For each user on the system, edit their local $HOME/.xscreensaver file and change the timeout values.

# pfedit $HOME/.xscreensaver

Find the timeout control lines and change them to read:

timeout: 0:15:00
lockTimeout:0:00:05
lock: True

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_SOL_11_SPARC_V3R1_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-11a., CAT|II, CCI|CCI-000057, Rule-ID|SV-216337r958402_rule, STIG-ID|SOL-11.1-040180, STIG-Legacy|SV-60919, STIG-Legacy|V-48047, Vuln-ID|V-216337

Plugin: Unix

Control ID: f7c74bbd0c0067743b7579ec4646c658639dba7484ea1f0efdd392e6530d817d