800-53|AC-11

Title

SESSION LOCK

Description

The information system:

Supplemental

Session locks are temporary actions taken when users stop work and move away from the immediate vicinity of information systems but do not want to log out because of the temporary nature of their absences. Session locks are implemented where session activities can be determined. This is typically at the operating system level, but can also be at the application level. Session locks are not an acceptable substitute for logging out of information systems, for example, if organizations require users to log out at the end of workdays.

Reference Item Details

Related: AC-7

Category: ACCESS CONTROL

Family: ACCESS CONTROL

Priority: P3

Baseline Impact: MODERATE,HIGH

Audit Items

View all Reference Audit Items

NamePluginAudit Name
1.1.3.6.2 Set 'Interactive logon: Smart card removal behavior' to 'Lock Workstation'WindowsCIS Windows 8 L1 v1.0.0
1.1.3.6.10 Set 'Interactive logon: Machine inactivity limit' to '900 or fewer seconds'WindowsCIS Windows 8 L1 v1.0.0
1.1.3.9.14 Set 'MSS: (ScreenSaverGracePeriod) The time in seconds before the screen saver grace period expires (0 recommended)' to '0'WindowsCIS Windows 8 L1 v1.0.0
1.1.4 - AirWatch - Set 'timeout in minutes' for 'Sleep'MDMAirWatch - CIS Google Android 4 v1.0.0 L1
1.1.4 - AirWatch - Set Auto-lock - 'Inactivity Timeout <= 2'MDMAirWatch - CIS Apple iOS 8 v1.0.0 L1
1.1.4 - AirWatch - Set Auto-lock - 'Inactivity Timeout <= 2'MDMAirWatch - CIS Apple iOS 9 v1.0.0 L1
1.1.4 - MobileIron - Set 'timeout in minutes' for 'Sleep'MDMMobileIron - CIS Google Android 4 v1.0.0 L1
1.1.4 - MobileIron - Set Auto-lock - 'Inactivity Timeout <= 2'MDMMobileIron - CIS Apple iOS 9 v1.0.0 L1
1.1.4 - MobileIron - Set Auto-lock - 'Inactivity Timeout <= 2'MDMMobileIron - CIS Apple iOS 8 v1.0.0 L1
1.2.1 (L1) Ensure 'Account lockout duration' is set to '15 or more minute(s)'WindowsCIS Microsoft Windows 8.1 v2.4.1 L1 Bitlocker
1.2.1 Ensure 'Account lockout duration' is set to '15 or more minute(s)'WindowsCIS Microsoft Windows 8.1 v2.4.1 L1
1.2.2 (L1) Ensure 'Account lockout threshold' is set to '10 or fewer invalid logon attempt(s), but not 0'WindowsCIS Microsoft Windows 8.1 v2.4.1 L1 Bitlocker
1.2.2 Ensure 'Account lockout threshold' is set to '10 or fewer invalid logon attempt(s), but not 0'WindowsCIS Microsoft Windows 8.1 v2.4.1 L1
1.2.3 (L1) Ensure 'Reset account lockout counter after' is set to '15 or more minute(s)'WindowsCIS Microsoft Windows 8.1 v2.4.1 L1 Bitlocker
1.2.3 Ensure 'Reset account lockout counter after' is set to '15 or more minute(s)'WindowsCIS Microsoft Windows 8.1 v2.4.1 L1
1.2.6 Set 'exec-timeout' to less than or equal to 10 minutes for 'line aux 0'CiscoCIS Cisco IOS 15 L1 v4.1.1
1.2.6 Set 'exec-timeout' to less than or equal to 10 minutes for 'line aux 0'CiscoCIS Cisco IOS XE 16.x v2.2.0 L1
1.2.6 Set 'exec-timeout' to less than or equal to 10 minutes for 'line aux 0'CiscoCIS Cisco IOS XE 17.x v2.2.1 L1
1.2.7 Set 'exec-timeout' to less than or equal to 10 minutes 'line console 0'CiscoCIS Cisco IOS 15 L1 v4.1.1
1.2.7 Set 'exec-timeout' to less than or equal to 10 minutes 'line console 0'CiscoCIS Cisco IOS XE 16.x v2.2.0 L1
1.2.7 Set 'exec-timeout' to less than or equal to 10 minutes 'line console 0'CiscoCIS Cisco IOS XE 17.x v2.2.1 L1
1.2.8 Set 'exec-timeout' less than or equal to 10 minutes 'line tty'CiscoCIS Cisco IOS 15 L1 v4.1.1
1.2.8 Set 'exec-timeout' to less than or equal to 10 minutes 'line vty'CiscoCIS Cisco IOS XE 17.x v2.2.1 L1
1.2.8 Set 'exec-timeout' to less than or equal to 10 minutes 'line vty'CiscoCIS Cisco IOS XE 16.x v2.2.0 L1
1.2.9 Set 'exec-timeout' to less than or equal to 10 minutes 'line vty'CiscoCIS Cisco IOS 15 L1 v4.1.1
1.2.9 Set 'transport input none' for 'line aux 0'CiscoCIS Cisco IOS XE 16.x v2.2.0 L1
1.2.10 Set 'exec-timeout' to less than or equal to 10 minutes 'line vty'CiscoCIS Cisco IOS 15 L1 v4.1.1
1.2.11 Set 'exec-timeout' to less than or equal to 10 min on 'ip http'CiscoCIS Cisco IOS XE 16.x v2.2.0 L1
1.2.11 Set 'transport input none' for 'line aux 0'CiscoCIS Cisco IOS 15 L1 v4.1.1
1.11 Ensure Deny access after failed login attempts is selectedCheckPointCIS Check Point Firewall L1 v1.1.0
1.12 Ensure Maximum number of failed attempts allowed is set to 5 or fewerCheckPointCIS Check Point Firewall L1 v1.1.0
1.13 Ensure Allow access again after time is set to 300 or more secondsCheckPointCIS Check Point Firewall L1 v1.1.0
1.21 Ensure 'Screen timeout' is set to '1 minute or less'MDMMobileIron - CIS Google Android v1.3.0 L1
1.21 Ensure 'Screen timeout' is set to '1 minute or less'MDMAirWatch - CIS Google Android v1.3.0 L1
1.23 Ensure 'Sleep' is set to 1 minute or lessMDMAirWatch - CIS Google Android 7 v1.0.0 L1
1.155 OL08-00-020030UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
1.156 OL08-00-020031UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
1.159 OL08-00-020043UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
1.160 OL08-00-020050UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
1.161 OL08-00-020060UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
1.162 OL08-00-020080UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
1.163 OL08-00-020081UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
1.164 OL08-00-020082UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
1.200 WN10-SO-000070WindowsCIS Microsoft Windows 10 STIG v1.0.0 CAT II
1.217 WN16-SO-000140WindowsCIS Microsoft Windows Server 2016 STIG v4.0.0 DC CAT II
1.217 WN16-SO-000140WindowsCIS Microsoft Windows Server 2016 STIG v4.0.0 MS CAT II
1.219 WN19-SO-000120WindowsCIS Microsoft Windows Server 2019 STIG v4.0.0 MS CAT II
1.219 WN19-SO-000120WindowsCIS Microsoft Windows Server 2019 STIG v4.0.0 DC CAT II
1.219 WN22-SO-000120WindowsCIS Microsoft Windows Server 2022 STIG v3.0.0 DC CAT II
1.219 WN22-SO-000120WindowsCIS Microsoft Windows Server 2022 STIG v3.0.0 MS CAT II