5.10 Require a password to wake the computer from sleep or screen saver

Information

Sleep and screensaver modes are low power modes that reduces electrical consumption while the system is not in use.

Rationale:

Prompting for a password when waking from sleep or screensaver mode mitigates the threat of an unauthorized person gaining access to a system in the user's absence.

Impact:

Without a screenlock in place anyone with physical access to the computer would be logged in and able to use the active users session.

Solution

Perform the following to implement the prescribed state:

Run the following command in Terminal: The current user will need to log off and on for changes to take effect.

defaults write com.apple.screensaver askForPassword -int 1



The current user will need to log off and on for changes to take effect.

Additional Information:

This only protects the system when the screen saver is running.

See Also

https://workbench.cisecurity.org/files/3092

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-11, CSCv6|16.5

Plugin: Unix

Control ID: b563a9b55c2b061a34998e8bad7649134b024f69101769464295a2298bbec74a