AC.L2-3.1.10Session Lock
Use session lock with pattern-hiding displays to prevent access and viewing of data after a period of inactivity.
[a]
the period of inactivity after which the system initiates a session lock is defined;[b]
access to the system and viewing of data is prevented by initiating a session lock after the defined period of inactivity; and[c]
previously visible information is concealed via a pattern-hiding display after the defined period of inactivity.
Screen lock ≤15 minutes with pattern-hiding on CUI endpoints
Implementation
AO coverage. Addresses all Session Lock objectives for in-scope endpoints.
Windows. Intune profile: idle lock at 15 minutes or less, password/PIN required to resume, lock screen does not preview CUI notification content (pattern-hiding).
macOS. Configuration profile enforces screensaver lock ≤15 minutes with password on wake for enclave users.
Maintenance. Weekly compliance dashboard; devices noncompliant >3 days open a ticket. Users cannot locally raise the timeout.
Accepted gap. Shop-floor tablets that must stay readable during a shift use a supervised kiosk mode with auto-logoff at shift end instead of a short lock; they hold no CUI at rest.
What the evidence looks like
- Intune/macOS profile exports showing lock timeout and notification settings
- Compliance report sample
- Kiosk exception documentation
Environment
Tools
Was this example useful?
Quick reaction — no account needed. For reasoning that moves the community meter, cast a full verdict below.
Discussion(0)
No discussion on this example yet
Verdicts capture a conclusion. Use a thread when the interesting part is the argument.
Sign in to start a thread.