5.11 Disable ability to login to another user's active and locked session

Information

Disabling the admins and/or user's ability to log into another user's active and locked session prevents unauthorized persons from viewing potentially sensitive and/or personal information.

Solution

Perform the following to implement the prescribed state:
sudo vi /etc/pam.d/screensaver
Locate 'account required pam_group.so no_warn group=admin,wheel fail_safe'
Remove 'admin,'
Save

See Also

https://workbench.cisecurity.org/files/301

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-10

Plugin: Unix

Control ID: 603c2a6b761e106f74b7d2b31857cca41e67d994bfff3e5b3dbe4856a8e6d824