Configure automatic session locking on enterprise assets after a defined period of inactivity. For general purpose operating systems, the period must not exceed 15 minutes. For mobile end-user devices, the period must not exceed 2 minutes.
| Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
|---|---|---|---|---|---|
| CIS-4.3 | Configure Automatic Session Locking on Enterprise Assets | mitigates | T1078 | Valid Accounts |
Comments
The safeguard forces a renewed authentication checkpoint after inactivity and therefore reduces any possibility of opportunistic use of a still-authenticated user on an open unlocked enterprise asset.
References
|