UCF STIG Viewer Logo

The system will be configured to have password protection take effect within a limited time frame when the screen saver becomes active.


Overview

Finding ID Version Rule ID IA Controls Severity
V-4442 5.102 SV-32360r1_rule PESL-1 Low
Description
Allowing more than several seconds for password protection to take effect when a screen saver becomes active makes the computer vulnerable to a potential attack from someone walking up to the console to attempt to access the system.
STIG Date
Windows Server 2008 R2 Domain Controller Security Technical Implementation Guide 2014-07-09

Details

Check Text ( None )
None
Fix Text (F-28833r1_fix)
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> “MSS: (ScreenSaverGracePeriod) The time in seconds before the screen saver grace period expires (0 recommended)” to “5” or less.