3.1.5 - AirWatch - Set the 'timeout' for 'Time without user input before password must be re-entered (in minutes)'

Information

This control defines the number of minutes the device can be inactive before requiring the password be reentered. By default, if a passcode is defined, an iOS device will automatically lock after two minutes of inactivity, and the default Exchange ActiveSync policy setting applied for users not assigned to a mailbox policy sets an inactivity lock at 15 minutes. The recommended setting is 2 minutes or less.

Solution

From the AirWatch console, open the iOS device profile. Under Passcode verify that Auto-Lock is set to a value of 2 minutes or less.

See Also

https://workbench.cisecurity.org/files/447

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-11, CSCv6|16.5

Plugin: MDM

Control ID: 40dfc9d5c909960be4935443cb6649f6d3e7a5bbea82633e8d80f2f96611e5f9