800-53|AC-11

Title

SESSION LOCK

Description

The information system:

Supplemental

Session locks are temporary actions taken when users stop work and move away from the immediate vicinity of information systems but do not want to log out because of the temporary nature of their absences. Session locks are implemented where session activities can be determined. This is typically at the operating system level, but can also be at the application level. Session locks are not an acceptable substitute for logging out of information systems, for example, if organizations require users to log out at the end of workdays.

Reference Item Details

Related: AC-7

Category: ACCESS CONTROL

Family: ACCESS CONTROL

Priority: P3

Baseline Impact: MODERATE,HIGH

Audit Items

View all Reference Audit Items

NamePluginAudit Name
1.1.3.6.2 Set 'Interactive logon: Smart card removal behavior' to 'Lock Workstation'WindowsCIS Windows 8 L1 v1.0.0
1.1.3.6.10 Set 'Interactive logon: Machine inactivity limit' to '900 or fewer seconds'WindowsCIS Windows 8 L1 v1.0.0
1.1.3.9.14 Set 'MSS: (ScreenSaverGracePeriod) The time in seconds before the screen saver grace period expires (0 recommended)' to '0'WindowsCIS Windows 8 L1 v1.0.0
1.1.4 - AirWatch - Set 'timeout in minutes' for 'Sleep'MDMAirWatch - CIS Google Android 4 v1.0.0 L1
1.1.4 - AirWatch - Set Auto-lock - 'Inactivity Timeout <= 2'MDMAirWatch - CIS Apple iOS 8 v1.0.0 L1
1.1.4 - AirWatch - Set Auto-lock - 'Inactivity Timeout <= 2'MDMAirWatch - CIS Apple iOS 9 v1.0.0 L1
1.1.4 - MobileIron - Set 'timeout in minutes' for 'Sleep'MDMMobileIron - CIS Google Android 4 v1.0.0 L1
1.1.4 - MobileIron - Set Auto-lock - 'Inactivity Timeout <= 2'MDMMobileIron - CIS Apple iOS 9 v1.0.0 L1
1.1.4 - MobileIron - Set Auto-lock - 'Inactivity Timeout <= 2'MDMMobileIron - CIS Apple iOS 8 v1.0.0 L1
1.2.1 (L1) Ensure 'Account lockout duration' is set to '15 or more minute(s)'WindowsCIS Microsoft Windows 8.1 v2.4.1 L1 Bitlocker
1.2.1 Ensure 'Account lockout duration' is set to '15 or more minute(s)'WindowsCIS Microsoft Windows 8.1 v2.4.1 L1
1.2.2 (L1) Ensure 'Account lockout threshold' is set to '10 or fewer invalid logon attempt(s), but not 0'WindowsCIS Microsoft Windows 8.1 v2.4.1 L1 Bitlocker
1.2.2 Ensure 'Account lockout threshold' is set to '10 or fewer invalid logon attempt(s), but not 0'WindowsCIS Microsoft Windows 8.1 v2.4.1 L1
1.2.3 (L1) Ensure 'Reset account lockout counter after' is set to '15 or more minute(s)'WindowsCIS Microsoft Windows 8.1 v2.4.1 L1 Bitlocker
1.2.3 Ensure 'Reset account lockout counter after' is set to '15 or more minute(s)'WindowsCIS Microsoft Windows 8.1 v2.4.1 L1
1.2.6 Set 'exec-timeout' to less than or equal to 10 minutes for 'line aux 0'CiscoCIS Cisco IOS XE 16.x v2.1.0 L1
1.2.6 Set 'exec-timeout' to less than or equal to 10 minutes for 'line aux 0'CiscoCIS Cisco IOS 15 L1 v4.1.1
1.2.6 Set 'exec-timeout' to less than or equal to 10 minutes for 'line aux 0'CiscoCIS Cisco IOS XE 17.x v2.1.0 L1
1.2.7 Set 'exec-timeout' to less than or equal to 10 minutes 'line console 0'CiscoCIS Cisco IOS XE 16.x v2.1.0 L1
1.2.7 Set 'exec-timeout' to less than or equal to 10 minutes 'line console 0'CiscoCIS Cisco IOS 15 L1 v4.1.1
1.2.7 Set 'exec-timeout' to less than or equal to 10 minutes 'line console 0'CiscoCIS Cisco IOS XE 17.x v2.1.0 L1
1.2.8 Set 'exec-timeout' less than or equal to 10 minutes 'line tty'CiscoCIS Cisco IOS 15 L1 v4.1.1
1.2.8 Set 'exec-timeout' to less than or equal to 10 minutes 'line vty'CiscoCIS Cisco IOS XE 16.x v2.1.0 L1
1.2.8 Set 'exec-timeout' to less than or equal to 10 minutes 'line vty'CiscoCIS Cisco IOS XE 17.x v2.1.0 L1
1.2.9 Set 'exec-timeout' to less than or equal to 10 minutes 'line vty'CiscoCIS Cisco IOS 15 L1 v4.1.1
1.2.9 Set 'transport input none' for 'line aux 0'CiscoCIS Cisco IOS XE 17.x v2.1.0 L1
1.2.9 Set 'transport input none' for 'line aux 0'CiscoCIS Cisco IOS XE 16.x v2.1.0 L1
1.2.10 Set 'exec-timeout' to less than or equal to 10 minutes 'line vty'CiscoCIS Cisco IOS 15 L1 v4.1.1
1.2.11 Set 'exec-timeout' to less than or equal to 10 min on 'ip http'CiscoCIS Cisco IOS XE 17.x v2.1.0 L1
1.2.11 Set 'exec-timeout' to less than or equal to 10 min on 'ip http'CiscoCIS Cisco IOS XE 16.x v2.1.0 L1
1.2.11 Set 'transport input none' for 'line aux 0'CiscoCIS Cisco IOS 15 L1 v4.1.1
1.3.2 Ensure 'Idle session timeout' is set to '3 hours (or less)' for unmanaged devicesmicrosoft_azureCIS Microsoft 365 Foundations E3 L1 v3.1.0
1.4.1 Ensure 'Idle timeout' is less than or equal to 10 minutes for device managementPalo_AltoCIS Palo Alto Firewall 10 v1.2.0 L1
1.4.1 Ensure 'Idle timeout' is less than or equal to 10 minutes for device managementPalo_AltoCIS Palo Alto Firewall 8 Benchmark L1 v1.0.0
1.4.1 Ensure 'Idle timeout' is less than or equal to 10 minutes for device managementPalo_AltoCIS Palo Alto Firewall 11 v1.1.0 L1
1.4.1 Ensure 'Idle timeout' is less than or equal to 10 minutes for device managementPalo_AltoCIS Palo Alto Firewall 9 v1.1.0 L1
1.4.2 Ensure 'Failed Attempts' and 'Lockout Time' for Authentication Profile are properly configuredPalo_AltoCIS Palo Alto Firewall 10 v1.2.0 L1
1.4.2 Ensure 'Failed Attempts' and 'Lockout Time' for Authentication Profile are properly configuredPalo_AltoCIS Palo Alto Firewall 11 v1.1.0 L1
1.7.4 Ensure GDM screen locks when the user is idleUnixCIS Ubuntu Linux 24.04 LTS v1.0.0 L1 Workstation
1.7.4 Ensure GDM screen locks when the user is idleUnixCIS Debian Linux 12 v1.1.0 L1 Server
1.7.4 Ensure GDM screen locks when the user is idleUnixCIS CentOS Linux 7 v4.0.0 L1 Workstation
1.7.4 Ensure GDM screen locks when the user is idleUnixCIS Ubuntu Linux 22.04 LTS v2.0.0 L1 Server
1.7.4 Ensure GDM screen locks when the user is idleUnixCIS Debian Linux 11 v2.0.0 L1 Server
1.11 Ensure Deny access after failed login attempts is selectedCheckPointCIS Check Point Firewall L1 v1.1.0
1.12 Ensure Maximum number of failed attempts allowed is set to 5 or fewerCheckPointCIS Check Point Firewall L1 v1.1.0
1.13 Ensure Allow access again after time is set to 300 or more secondsCheckPointCIS Check Point Firewall L1 v1.1.0
1.21 Ensure 'Screen timeout' is set to '1 minute or less'MDMMobileIron - CIS Google Android v1.3.0 L1
1.21 Ensure 'Screen timeout' is set to '1 minute or less'MDMAirWatch - CIS Google Android v1.3.0 L1
1.23 Ensure 'Sleep' is set to 1 minute or lessMDMAirWatch - CIS Google Android 7 v1.0.0 L1
1.23 Ensure 'Sleep' is set to 1 minute or lessMDMMobileIron - CIS Google Android 7 v1.0.0 L1