5.11 Disable ability to login to another user's active and locked session

Information

Disabling the admins and/or user's ability to log into another user's active and locked session prevents unauthorized persons from viewing potentially sensitive and/or personal information.

Solution

Perform the following to implement the prescribed state:
sudo vi /etc/pam.d/screensaver
Locate 'account required pam_group.so no_warn group=admin,wheel fail_safe'
Remove 'admin,'
Save

See Also

https://workbench.cisecurity.org/files/300

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-10

Plugin: Unix

Control ID: 04409e30b2037aa56cd626464e08b608a218bd9a9796be155c3e670803179f98