2.3.3 Familiarize users with screen lock tools or corner to Start Screen Saver

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

In 10.13 Apple added a 'Lock Screen' option to the Apple Menu. Prior to this the best quick lock options were to use either a lock screen option with the screen saver or the lock screen option from Keychain Access if status was made available in the menu bar. With 10.13 the menu bar option is no longer available.
The intent of this control is to resemble control-alt-delete on Windows Systems as a means of quickly locking the screen. If the user of the system is stepping away from the computer the best practice is to lock the screen and setting a hot corner is an appropriate method.

Rationale:

Ensuring the user has a quick method to lock their screen may reduce opportunity for individuals in close physical proximity of the device to see screen contents.

Solution

Ensure users know how to lock screen using the Apple Menu 'Lock Screen' option when briefly stepping away from the computer.

Alternatively
In System Preferences: Desktop & Screen Saver: Screen Saver: Hot Corners, make sure at least one Active Screen Corner is set to Start Screen Saver. Make sure the user knows about this feature.

The screen corners can be set using the defaults command, but the permutations of combinations are many. The plist file to check is '~/Library/Preferences/com.apple.dock' and the keys are

wvous-bl-corner
wvous-br-corner
wvous-tl-corner
wvous-tr-corner

There are also modifier keys to check and various values for each of these keys. A value of '5' means the corner will start the screen saver. The corresponding wvous-xx-modifier key should be set to '0'.

See Also

https://workbench.cisecurity.org/files/2105

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-11

Plugin: Unix

Control ID: e227d80f10a1612ee9e2546e2ea373bc70c33fce73e2ef33ea2ad1ff366cbd9f