The terminal or workstation must lock out after a maximum of 15 minutes of inactivity, requiring the account password to resume.

Overview

Finding IDVersionRule IDIA ControlsSeverity
V-256883HMC0150SV-256883r958402_ruleCCI-000057medium
Description
If the system, workstation, or terminal does not lock the session after more than15 minutes of inactivity, requiring a password to resume operations, the system or individual data could be compromised by an alert intruder who could exploit the oversight.
STIGDate
IBM Hardware Management Console (HMC) Security Technical Implementation Guide2024-06-24

Related Frameworks

3 paths across 3 frameworks
NIST 800-531 mapping
AC-11
1.00
  • DISA · V2R1 · disa_xccdf · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
NIST 800-1711 mapping
3.1.10
1.00
  • DISA · V2R1 · disa_xccdf · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
CCI1 mapping
CCI-000057
1.00
  • DISA · V2R1 · disa_xccdf · related

Details

Check Text (C-256883r958402_chk)

Have the System Administrator display the User Properties window on the Hardware Management Console and check that the timeout minutes are set to a maximum of 15. If the Verify Timeout minutes are set to more than 15, then this is a FINDING.

Fix Text (F-60501r890994_fix)

The System Administrator will display the User Properties window and will ensure that the Verify timeout minutes are set to a maximum of 15.