STIGQter STIGQter: STIG Summary: Solaris 11 X86 Security Technical Implementation Guide Version: 2 Release: 3 Benchmark Date: 23 Apr 2021:

The operating system must provide the capability for users to directly initiate session lock mechanisms.

DISA Rule

SV-216126r603268_rule

Vulnerability Number

V-216126

Group Title

SRG-OS-000030

Rule Version

SOL-11.1-040460

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

User-initiated session lock is accessible from the GNOME graphical desktop menu GNOME 2: System >> Lock Screen.

GNOME 3: Status Menu (top right corner) >> Lock Icon.

However, the user has the option to disable screensaver lock.

For Solaris 11, 11.1, 11.2, and 11.3:
In the GNOME 2 desktop: System >> Preferences >> Screensaver.

For Solaris 11.4 or newer:
If using the default GNOME desktop: Activities >> Show Applications >> select "Screensaver" Icon.

If using the GNOME Classic desktop: Applications >> Other >> Screensaver.

Ensure that "Mode" is set to "Blank Screen only".

Check Contents

Determine whether the lock screen function works correctly.

For Solaris 11, 11.1, 11.2, and 11.3:
In the GNOME 2 desktop System >> Lock Screen.

For Solaris 11.4 or newer:
In the GNOME 3 desktop Status Menu (top right corner) >> Lock Icon, check that the screen locks and displays the "password" prompt.

Check that "Disable Screensaver" is not selected in the GNOME Screensaver preferences.

If the screen does not lock or the "Disable Screensaver" option is selected, this is a finding.

Vulnerability Number

V-216126

Documentable

False

Rule Version

SOL-11.1-040460

Severity Override Guidance

Determine whether the lock screen function works correctly.

For Solaris 11, 11.1, 11.2, and 11.3:
In the GNOME 2 desktop System >> Lock Screen.

For Solaris 11.4 or newer:
In the GNOME 3 desktop Status Menu (top right corner) >> Lock Icon, check that the screen locks and displays the "password" prompt.

Check that "Disable Screensaver" is not selected in the GNOME Screensaver preferences.

If the screen does not lock or the "Disable Screensaver" option is selected, this is a finding.

Check Content Reference

M

Target Key

4021

Comments