5.4.5 Ensure default user shell timeout is 900 seconds or less - /etc/profile

Information

The default TMOUT determines the shell timeout for users. The TMOUT value is measured in seconds.

Rationale:

Having no timeout value associated with a shell could allow an unauthorized user access to another user's shell session (e.g. user walks away from their computer and doesn't lock the screen). Setting a timeout value at least reduces the risk of this happening.

Solution

Edit the /etc/bashrc and /etc/profile files (and the appropriate files for any other shell supported on your system) and add or edit any umask parameters as follows:

TMOUT=600

See Also

https://workbench.cisecurity.org/files/2449

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-11, CSCv7|16.11

Plugin: Unix

Control ID: 9b8e95dcdbb52f6540fa2a18bc7727a06dc1d79412e7952961253cd54614192a