device lock
A security control that temporarily suspends logical access to a system or device — requiring re-authentication before use resumes — when a session has been idle for a defined period or when a user steps away without logging out. Device locks are temporary actions taken to prevent logical access to organizational systems when users stop work and move away from the immediate vicinity of those systems but do not want to log out because of the temporary nature of their absences. The control is distinct from full session termination: device locks are not an acceptable substitute for logging out of the system (e.g., when organizations require users to log out at the end of workdays). In practice it is specified as a named access-control requirement — control AC-11 in NIST SP 800-53 and requirement 03.01.10 in NIST SP 800-171 — mandating both automatic triggering after inactivity and concealment of previously visible screen content, by concealing, via the device lock, information previously visible on the display with a publicly viewable image, and retaining the lock until the user reestablishes access using established identification and authentication procedures.
Framework senses
- §1 · web_lookup_draft
- A security control that temporarily suspends logical access to a system or device — requiring re-authentication before use resumes — when a session has been idle for a defined period or when a user steps away without logging out. Device locks are temporary actions taken to prevent logical access to organizational systems when users stop work and move away from the immediate vicinity of those systems but do not want to log out because of the temporary nature of their absences. The control is distinct from full session termination: device locks are not an acceptable substitute for logging out of the system (e.g., when organizations require users to log out at the end of workdays). In practice it is specified as a named access-control requirement — control AC-11 in NIST SP 800-53 and requirement 03.01.10 in NIST SP 800-171 — mandating both automatic triggering after inactivity and concealment of previously visible screen content, by concealing, via the device lock, information previously visible on the display with a publicly viewable image, and retaining the lock until the user reestablishes access using established identification and authentication procedures.Drafted by the propose-term web lookup (PD-018); a curator confirms or replaces it.