home/glossary/device lock

device lock

nounid 163609·updated Sep 15, 2026
candidate

A security control that temporarily suspends logical access to a system or device — requiring re-authentication before use resumes — when a session has been idle for a defined period or when a user steps away without logging out. Device locks are temporary actions taken to prevent logical access to organizational systems when users stop work and move away from the immediate vicinity of those systems but do not want to log out because of the temporary nature of their absences. The control is distinct from full session termination: device locks are not an acceptable substitute for logging out of the system (e.g., when organizations require users to log out at the end of workdays). In practice it is specified as a named access-control requirement — control AC-11 in NIST SP 800-53 and requirement 03.01.10 in NIST SP 800-171 — mandating both automatic triggering after inactivity and concealment of previously visible screen content, by concealing, via the device lock, information previously visible on the display with a publicly viewable image, and retaining the lock until the user reestablishes access using established identification and authentication procedures.

MWE

Source

document
NIST SP 800-171 Rev 3 - Protecting CUI in Nonfederal Systems
found in
proposed during MWE review from candidate:residue_v1
element
e0235
proposed by
dorianc@moxywolf.com
discovery
ManualCuration
Device Lockthe sentence this term was read in
Where the definition came fromawaiting curator confirmation

generalized from a web lookup of the quoted expression at proposal time Verdict: term of art.

A definition generalized from search results is a draft to react to, not provenance. Confirm it against an authority document before this term is verified.

A web lookup ran when this term was proposed

A security control that temporarily suspends logical access to a system or device — requiring re-authentication before use resumes — when a session has been idle for a defined period or when a user steps away without logging out. Device locks are temporary actions taken to prevent logical access to organizational systems when users stop work and move away from the immediate vicinity of those systems but do not want to log out because of the temporary nature of their absences. The control is distinct from full session termination: device locks are not an acceptable substitute for logging out of the system (e.g., when organizations require users to log out at the end of workdays). In practice it is specified as a named access-control requirement — control AC-11 in NIST SP 800-53 and requirement 03.01.10 in NIST SP 800-171 — mandating both automatic triggering after inactivity and concealment of previously visible screen content, by concealing, via the device lock, information previously visible on the display with a publicly viewable image, and retaining the lock until the user reestablishes access using established identification and authentication procedures.

Advisory only. A term this product ships is defined by an authority document, not by a search result.

Proposed during multiword review of this document in the CKI mapping queue.

Attested in

No recorded attestations. They are written when an MWE tagging stage is completed, stamped with the pack version and the document’s digest.

Classifications

Entity Type

Unknownauthoritativecki_proposal_default_pending_classifier

Sensitivity

unclassified

Information Class

unclassified

Variants

plural
device locks
possessive
device lock's
pluralpossessive
device locks'

Framework definitions

Web lookup drafts1 senseview framework →
§1 · web_lookup_draft
A security control that temporarily suspends logical access to a system or device — requiring re-authentication before use resumes — when a session has been idle for a defined period or when a user steps away without logging out. Device locks are temporary actions taken to prevent logical access to organizational systems when users stop work and move away from the immediate vicinity of those systems but do not want to log out because of the temporary nature of their absences. The control is distinct from full session termination: device locks are not an acceptable substitute for logging out of the system (e.g., when organizations require users to log out at the end of workdays). In practice it is specified as a named access-control requirement — control AC-11 in NIST SP 800-53 and requirement 03.01.10 in NIST SP 800-171 — mandating both automatic triggering after inactivity and concealment of previously visible screen content, by concealing, via the device lock, information previously visible on the display with a publicly viewable image, and retaining the lock until the user reestablishes access using established identification and authentication procedures.
Drafted by the propose-term web lookup (PD-018); a curator confirms or replaces it.

Outgoing relationships

No outgoing triples
This term is not the subject of any RDF-style relationship yet.

Incoming relationships

No incoming triples
No other term currently asserts a relationship to this one.