id: "AC-11" title: "Device Lock" family: "AC" family_name: "Access Control" sort_id: "ac-11" priority: "P1" implementation_level: "system" enhancements: - ac-11.1


Prevent further access to the system by {{ insert: param, ac-11_odp.01 }} ; and

Retain the device lock until the user reestablishes access using established identification and authentication procedures.

Guidance

Device locks are temporary actions taken to prevent logical access to organizational systems when users stop work and move away from the immediate vicinity of those systems but do not want to log out because of the temporary nature of their absences. Device locks can be implemented at the operating system level or at the application level. A proximity lock may be used to initiate the device lock (e.g., via a Bluetooth-enabled device or dongle). User-initiated device locking is behavior or policy-based and, as such, requires users to take physical action to initiate the device lock. Device locks are not an acceptable substitute for logging out of systems, such as when organizations require users to log out at the end of workdays.

Assessment Objective: further access to the system is prevented by {{ insert: param, ac-11_odp.01 }};

Assessment Objective: device lock is retained until the user re-establishes access using established identification and authentication procedures.

Access control policy

procedures addressing session lock

procedures addressing identification and authentication

system design documentation

system configuration settings and associated documentation

security plan

system security plan

other relevant documents or records

System/network administrators

organizational personnel with information security responsibilities

system developers

Mechanisms implementing access control policy for session lock