5.5 Ensure login keychain is locked when the computer sleeps

Information

While logged in, the keychain does not prompt the user for passwords for various systems and/or programs. This can be exploited by unauthorized users to gain access to password protected programs and/or systems in the absence of the user.

Solution

Perform the following to implement the prescribed state:
Open Utilities
Select Keychain Access
Select a keychain
Select Edit
Select Change Settings for keychain <keychain_name>
Authenticate, if requested.
Select Lock when sleeping setting

See Also

https://workbench.cisecurity.org/files/301

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(13)

Plugin: Unix

Control ID: e65089b7c676c24d0327eae5ecb84f6bbe4e9f103b0099bf13845cb8772a5713