1.3 Ensure 'Make pattern visible' is set to 'Disabled' (if using a pattern as device lock mechanism)

Information

Disable pattern visibility if using a pattern as device lock mechanism.
The recommended state for this setting is: Disabled.

Rationale:

Keeping device unlock pattern visible during device unlock can reveal the pattern and is vulnerable to shoulder surfing attack. Hence, do not make the device unlock pattern visible.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

To disable device unlock pattern visibility, follow the below steps:

Tap Settings Gear Icon.
Tap Security.
Scroll to the Device security section.
If Screen lock has Pattern underneath the text, follow further steps. If not, then this recommendation is not applicable.
Tap the Gear Icon next to Screen lock.
Toggle Make pattern visible to OFF position.

Impact:

The user would have to be careful while entering the device unlock pattern since visual feedback would not provide any clues for tracing pattern input.

Default Value:

By default, device unlock pattern is visible.

See Also

https://workbench.cisecurity.org/files/2466

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b.

Plugin: MDM

Control ID: 6af2d3d9b8c43a7d67bcd9e942793ad66d3761b91548cadb3b1b251b9f24dea4