Skip to content
ControlVerdict
AC.L2-3.1.10addresses
AC.L2-3.1.10Session Lock
Use session lock with pattern-hiding displays to prevent access and viewing of data after a period of inactivity.
  • [a]

    the period of inactivity after which the system initiates a session lock is defined;
  • [b]

    access to the system and viewing of data is prevented by initiating a session lock after the defined period of inactivity; and
  • [c]

    previously visible information is concealed via a pattern-hiding display after the defined period of inactivity.

View full control

Screen lock ≤15 minutes with pattern-hiding on CUI endpoints

ControlVerdict Corpus@cv-corpusOSCJul 31, 2026
Community is just starting — add yours. No verdicts yet.

Implementation

AO coverage. Addresses all Session Lock objectives for in-scope endpoints.

Windows. Intune profile: idle lock at 15 minutes or less, password/PIN required to resume, lock screen does not preview CUI notification content (pattern-hiding).

macOS. Configuration profile enforces screensaver lock ≤15 minutes with password on wake for enclave users.

Maintenance. Weekly compliance dashboard; devices noncompliant >3 days open a ticket. Users cannot locally raise the timeout.

Accepted gap. Shop-floor tablets that must stay readable during a shift use a supervised kiosk mode with auto-logoff at shift end instead of a short lock; they hold no CUI at rest.

What the evidence looks like

  • Intune/macOS profile exports showing lock timeout and notification settings
  • Compliance report sample
  • Kiosk exception documentation

Environment

Windows 11 CUI fleet managed by Intune; macOS engineers on a smaller baseline.

Tools

Was this example useful?

Quick reaction — no account needed. For reasoning that moves the community meter, cast a full verdict below.

Discussion(0)

No discussion on this example yet

Verdicts capture a conclusion. Use a thread when the interesting part is the argument.

Sign in to start a thread.