1.29 APPL-14-000160

Information

The macOS system must enforce auto logout after 86400 seconds of inactivity.

GROUP ID: V-259449RULE ID: SV-259449r958636

Auto logout must be configured to automatically terminate a user session and log out the after 86400 seconds of inactivity.

Note: The maximum that macOS can be configured for autologoff is 86400 seconds.

[IMPORTANT]

The automatic logout may cause disruptions to an organization's workflow and/or loss of data. Information system security officers (ISSOs) are advised to first fully weigh the potential risks posed to their organization before opting to disable the automatic logout setting.

Solution

Configure the macOS system to enforce auto logout after 86400 seconds of inactivity by installing the "com.apple.GlobalPreferences" configuration profile.

See Also

https://workbench.cisecurity.org/benchmarks/24070

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-12, CAT|II, CCI|CCI-002361, Rule-ID|SV-259449r958636_rule, STIG-ID|APPL-14-000160, Vuln-ID|V-259449

Plugin: Unix

Control ID: 899d1a4417d88beafbce3afc602a4d87c2d1cb7e3ecc99f07fad37e6de1484bb