{"data":{"id":"AC-11","name":"Device Lock","family":"AC","family_name":"Access Control","withdrawn":false,"description":"a. Prevent further access to the system by [Selection (one or more): initiating a device lock after [Assignment: organization-defined time period] of inactivity; requiring the user to initiate a device lock before leaving the system unattended]; and\nb. Retain the device lock until the user reestablishes access using established identification and authentication procedures.","supplemental_guidance":"Device locks are temporary actions taken to prevent logical access to organizational systems when users stop work and move away from the immediate vicinity of those systems but do not want to log out because of the temporary nature of their absences. Device locks can be implemented at the operating system level or at the application level. A proximity lock may be used to initiate the device lock (e.g., via a Bluetooth-enabled device or dongle). User-initiated device locking is behavior or policy-based and, as such, requires users to take physical action to initiate the device lock. Device locks are not an acceptable substitute for logging out of systems, such as when organizations require users to log out at the end of workdays.","enhancements":[{"id":"AC-11(01)","name":"Pattern-hiding Displays","statement":"Conceal, via the device lock, information previously visible on the display with a publicly viewable image.","baselines":["moderate","high"]}],"baseline_low":false,"baseline_moderate":true,"baseline_high":true,"nist_800_53":{"rev5":{"id":"AC-11","name":"Device Lock","description":"a. Prevent further access to the system by [Selection (one or more): initiating a device lock after [Assignment: organization-defined time period] of inactivity; requiring the user to initiate a device lock before leaving the system unattended]; and\nb. Retain the device lock until the user reestablishes access using established identification and authentication procedures.","discussion":"Device locks are temporary actions taken to prevent logical access to organizational systems when users stop work and move away from the immediate vicinity of those systems but do not want to log out because of the temporary nature of their absences. Device locks can be implemented at the operating system level or at the application level. A proximity lock may be used to initiate the device lock (e.g., via a Bluetooth-enabled device or dongle). User-initiated device locking is behavior or policy-based and, as such, requires users to take physical action to initiate the device lock. Device locks are not an acceptable substitute for logging out of systems, such as when organizations require users to log out at the end of workdays.","related_controls":["AC-02","AC-07","IA-11","PL-04"],"baseline_low":false,"baseline_moderate":true,"baseline_high":true,"baseline_privacy":false,"new_in_rev5":false,"changes_from_rev4":"Title changed from ' the control to focus on device versus session Changes parameter to selection list  Amplifies how a device lock can be performed"}},"compliance_mappings":{"iso_27001_2022":["A.7.7","A.8.1"],"iso_27002_2022":["5.15","7.7"],"cobit_2019":["DSS05"],"pci_dss_v4":[],"nist_csf_2":[],"cis_controls_v8":["CIS 4.3","CIS 4.10"],"soc2_tsc":[],"finos_ccc":[],"iso_42001_2023":[],"iec_62443":[],"asd_e8":[],"nis2":["Art. 21(2)(i)"],"apra_cps_234":[],"mas_trm":["9"],"pra_op_resilience":[],"bsi_grundschutz":["ORP.4"],"anssi":["SecNumCloud.10.6"],"osfi_b13":["B-13.3.2"],"finma_circular":["IV.B.d(59)","IV.C(61)"],"gdpr":["Art.32(1)(b)"],"dora":["Art.9(4)(c)"],"bio2":["5.15","7.7"],"rbi_csf":["Annex1.8"],"fisc":["FISC.T2"],"lgpd_bcb":[],"hkma_tme1":["TME1.8.4"],"mlps_2":[],"dnb_good_practice":[],"cra":[],"swift_cscf":["SWIFT.2.6"],"cbb_tm":["TM-6"],"cbuae":["CR-4"],"nca_ecc":["2-2"],"qatar_nia":["AC"],"sama_csf":["3.1"],"uae_ia":["T9"],"bog_cisd":["CISD-VIII"],"bom_ctrm":["3.3"],"cbe_csf":["CTO-1"],"cbn_csf":["Part3.2"],"sa_js2":["JS2-7.1","JS2-8.1"],"bot_cyber":["Ch2.2"],"cpmi_pfmi":["CG.PR"],"eba_ict":["3.4.2"],"ecb_croe":["CROE.2.3.1"],"ffiec_is":["II.C.15"],"hipaa_sr":["§164.310(b)","§164.310(c)","§164.312(a)(1)","§164.312(a)(2)(iii)"],"iosco_cyber":["PROT-1"],"sebi_cscrf":["PR.AA"],"cmmc_2":["AC"],"nerc_cip":[],"nrc_73_54":[],"tsa_psd":[],"ieee_1686":["5.8"],"ferc_cip":[],"doe_c2m2":[],"api_1164":[],"awia":[],"iaea_nss":[],"pci_pts":[],"fips_140":[],"cbest":[],"tiber_eu":[],"pci_hsm":[],"common_criteria":["CC Part 2 — FRU/FTA/FTP"],"isae_3402":[],"fca_sysc_13":[],"fda_21_cfr_11":["§11.10(d)","§11.200(a)(1)(i)","§11.200(a)(1)(ii)"],"fda_cyber":[],"hitrust_csf":["01.c"],"iso_27799":["9.4"],"lloyds_ms":["MS8.3"],"naic_ds":["4-access"],"nhs_dspt":[],"pra_ss1_23":[],"solvency_ii":["EIOPA-ICT-4.4"],"owasp_masvs_v2":[],"csa_ccm_v4":["HRS-03","UEM-06"],"csa_aicm":["HRS-03","UEM-06"],"ccss_v9":[],"mica":[],"basel_sco60":[],"bssc":[],"sec_custody_digital":[],"dpdpa":[]},"attack_techniques":[{"id":"T1021.001","name":"Remote Desktop Protocol","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Session lock after inactivity timeout closes idle RDP sessions that adversaries could otherwise exploit for lateral movement, requiring re-authentication before the session can be reused and reducing the window for unauthorized access via unattended remote desktop connections."},{"id":"T1563.002","name":"RDP Hijacking","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Automatic session lock directly counters RDP hijacking by ensuring that disconnected or idle sessions cannot be resumed without re-authentication, preventing adversaries from attaching to abandoned sessions to gain lateral movement within the environment."}],"metadata":{"last_reviewed":"2026-10-03","review_notes":"2026-10-03: iso_27001_2022 A.8.1 added from NIST's SP 800-53 Rev 5 to ISO/IEC 27001:2022 crosswalk (OLIR entry 155), which OSA's mapping now takes as its base. 2026-10-03: baselines LMH to -MH, from NIST SP 800-53B Release 5.2.0.","mapping_status":"complete"},"function":"preventative","used_by_patterns":["SP-001","SP-008"]}}