| Review configuration settings to confirm the screen lock time-out set to 15 minutes or fewer. |
This check procedure is performed on both the iOS management tool and the iOS device.
Note: If an organization has multiple configuration profiles, then the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review.
In the management tool, verify the sum of the values assigned to "Maximum Auto-Lock time" and "Grace period for device lock" value is between 1 and 15 minutes. Alternatively, locate the text "maxGracePeriod" and "maxInactivity" and ensure the sum of their integer value is between 1 and 15 in the configuration profile (.mobileconfig file). For example:
Here, 5 + 5 = 10; this meets the requirement.
On the iOS device:
1. Open Settings app.
2. Tap "General".
3. Record the value displayed for "Auto-Lock".
4. Go back to the Setting app main menu.
5. Tap "Touch ID & Passcode" or "Passcode".
6. Enter current device passcode and tap "Done".
7. Record the value displayed for "Require Passcode" (Record 0 if the setting is "Immediately".
8. Verify the sum of the two recorded values is between 1 and 15 minutes.
Note: On some iOS devices, it is not possible to have a sum of exactly 15. In these cases, the sum must be less than 15. A sum of 16 does not meet the requirement.
If the sum of the "Auto-Lock" and "Require Passcode" is not between 1 and 15 minutes in the iOS management tool, if the sum of the values assigned to "maxGracePeriod" and "maxInactivity" is not between 1 and 15 minutes in the configuration profile, or if the sum of the values assigned to "Auto-Lock" and "Require Passcode" is not between 1 and 15 minutes, this is a finding.