home/glossary/device lock

device lock

nouncandidate·updated Sep 15, 2026

A security control that temporarily suspends logical access to a system or device — requiring re-authentication before use resumes — when a session has been idle for a defined period or when a user steps away without logging out. Device locks are temporary actions taken to prevent logical access to organizational systems when users stop work and move away from the immediate vicinity of those systems but do not want to log out because of the temporary nature of their absences. The control is distinct from full session termination: device locks are not an acceptable substitute for logging out of the system (e.g., when organizations require users to log out at the end of workdays). In practice it is specified as a named access-control requirement — control AC-11 in NIST SP 800-53 and requirement 03.01.10 in NIST SP 800-171 — mandating both automatic triggering after inactivity and concealment of previously visible screen content, by concealing, via the device lock, information previously visible on the display with a publicly viewable image, and retaining the lock until the user reestablishes access using established identification and authentication procedures.

MWEWeb lookup drafts

Classifications

Entity Type

Unknownauthoritativecki_proposal_default_pending_classifier
?unassignedlast reviewed

Sensitivity

unclassified

Information Class

unclassified

Variants

plural
device locks
possessive
device lock's
pluralpossessive
device locks'