The operating system must not allow an unattended or automatic logon to the system.

Overview

Finding IDVersionRule IDIA ControlsSeverity
V-203782SRG-OS-000480-GPOS-00229SV-203782r991591_ruleCCI-000366high
Description
Failure to restrict system access to authenticated users negatively impacts operating system security.
STIGDate
General Purpose Operating System Security Requirements Guide2024-12-04

Details

Check Text (C-203782r991591_chk)

If the operating system provides a public access service, such as a kiosk, this is not applicable. Verify the operating system does not allow an unattended or automatic logon to the system. If it does, this is a finding. Automatic logon as an authorized user allows access to any user with physical access to the operating system.

Fix Text (F-3907r375738_fix)

If the operating system provides a public access service, such as a kiosk, this is not applicable. Configure the operating system to not allow an unattended or automatic logon to the system. Automatic logon as an authorized user allows access to any user with physical access to the operating system.