Catalina - Enforce Session Lock After Screen Saver is Started

Information

A screen saver _MUST_ be enabled and the system _MUST_ be configured to require a password to unlock once the screensaver has been on for a maximum of five seconds.

An unattended system with an excessive grace period is vulnerable to a malicious user.

Solution

This is implemented by a Configuration Profile.

mobileconfig profile info:

com.apple.screensaver:
askForPasswordDelay:
5

See Also

https://github.com/usnistgov/macos_security

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-11, 800-53|AC-11b., CCE|CCE-84785-5, CCI|CCI-000056, STIG-ID|AOSX-15-000003

Plugin: Unix

Control ID: 80f99203cf7455a24b5f1e3131c57fc716f4ec8bc33714964d56476d1e316a54