2.5.10 Ensure a Password is Required to Wake the Computer From Sleep or Screen Saver Is Enabled

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Sleep and screen saver modes are low power modes that reduce electrical consumption while the system is not in use.

Rationale:

Prompting for a password when waking from sleep or screen saver mode mitigates the threat of an unauthorized person gaining access to a system in the user's absence.

Impact:

Without a screenlock in place anyone with physical access to the computer would be logged in and able to use the active user's session.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Perform the following to enable a password for unlock after a screen saver begins or after sleep:
Graphical Method:

Open System Preferences

Select Security & Privacy

Select General

Set Require password after or screensaver begins with a time of immediately or 5 seconds

Profile Method:

Create or edit a configuration profile with the PayloadType of com.apple.screensaver

Add the key askForPassword

Set the key to <true/>

Add the key askForPasswordDelay

Set the key to <integer><0,5></integer>

See Also

https://workbench.cisecurity.org/files/4002