1Overview
AC.L2-3.1.10 requires that a workstation lock itself after a period of inactivity and that the lock screen hide whatever was on the display. It addresses the ordinary risk of a logged-in machine left unattended, which on a manufacturing floor is not an edge case but a daily reality, where an operator steps away from a terminal that still holds an open drawing.
The control has two parts that are easy to miss as one. The session must lock after inactivity, and the lock must conceal what was previously displayed rather than freezing the last screen in view. A lock that leaves a controlled drawing visible behind it has prevented interaction but not viewing, and the requirement names both. The threshold is not fixed by the requirement, but it must be short enough to be meaningful, and the same lock should be available for a user to invoke deliberately when stepping away. A defined inactivity period, an enforced lock, and a pattern-hiding display together satisfy the control.
Use session lock with pattern-hiding displays to prevent access and viewing of data after a period of inactivity.
Two elements distinguish this from a simple screensaver. "Session lock" means the machine requires reauthentication to resume, not merely a moving image that clears on a keypress. "Pattern-hiding displays" means the lock screen obscures the prior content, so a passerby cannot read what was open. Both are required, and a screensaver that does not lock, or a lock that shows the underlying screen, satisfies only part of the control.
2The Assessment Objectives
NIST SP 800-171A decomposes 3.1.10 into three objectives: define the inactivity period, enforce the lock after it, and hide the previous display.
The period of inactivity after which the system initiates a session lock is defined. The organization has set how long a machine may sit idle before it locks.
Access to the system and viewing of data is prevented by initiating a session lock after the defined period of inactivity. The machine actually locks and requires reauthentication once the idle period passes.
Previously visible information is concealed via a pattern-hiding display when a session lock is initiated. The lock screen hides what was on the display rather than leaving it in view.
The three objectives are a threshold, a lock, and a concealment. The most frequently missed is the difference between [b] and a screensaver: a decorative timeout that does not require reauthentication satisfies neither the access nor the viewing element, and the assessor distinguishes the two directly.
3Failure Patterns
The failures gather on the shop floor, where locking behavior collides with how machines are actually used, and on the systems that central policy does not manage.
The shop-floor terminal that never locks
Locking is disabled on floor terminals because reauthenticating at a shared or awkward station interrupts the work, so the machine holding job files and drawings sits open all shift. This is the most common and most consequential failure of the control, and it usually cannot be fixed by the timeout alone; it needs a workable authentication approach for the floor, such as badge tap or fast user switching, so that locking does not stop production.
The screensaver mistaken for a lock
A machine set to show a screensaver after inactivity may not be set to lock, so the session resumes on any keypress with no authentication. The screensaver looks like compliance and is not, because objective [b] requires reauthentication and objective [c] requires the prior content to be hidden, neither of which a bare screensaver provides.
The timeout set too long to matter
An inactivity period measured in an hour or more technically satisfies objective [a] while defeating the purpose, because the unattended machine remains open through exactly the window in which someone would walk past it. The period has to be short enough to address the risk the control names.
The standalone and specialized machines left out
Session lock configured through Group Policy reaches domain-joined workstations and misses the workgroup machine, the standalone controller, and the specialized equipment interface, which are common on a shop floor and often display CUI. These systems need the lock applied directly or, where they cannot lock, a compensating physical control.
4Ownership
This is an IT-owned technical control whose one complication is the shop floor, where the operations side has to be part of finding a locking approach that does not impede production.
| Role | Responsibility for this control |
|---|---|
| IT lead or system administrator | Defines the inactivity period and enforces the lock and pattern-hiding display across workstations, including standalone and specialized systems. Owns the configuration evidence. |
| Operations or floor supervisor | Partners on a locking approach the floor will accept, such as badge-based reauthentication or fast switching, so that the control is sustained rather than disabled to keep the line moving. |
| Security or compliance lead | Confirms the inactivity period is short enough to be meaningful and that the lock conceals prior content on the systems that handle CUI. |
| Program lead | Includes session-lock coverage in periodic review, particularly for new floor equipment, and retains the record. |
5Tooling
The control is set with native lock and screensaver policy, and the meaningful work is applying it everywhere and solving the floor-authentication problem so the lock survives.
| Objectives | Tooling | What it provides |
|---|---|---|
| [a], [b], [c] | Group Policy machine inactivity limit and screen-saver lock settings | The inactivity timeout that triggers a locking, pattern-hiding screen requiring reauthentication on domain-joined systems. |
| [b], [c] standalone | Local policy or configuration baselines | The same lock and concealment on workgroup machines and local sign-ins outside Group Policy. |
| Floor practicality | Badge or smart-card reauthentication, fast user switching, proximity lock | An authentication method quick enough that locking does not impede floor work, which is what keeps the control from being disabled in practice. |
| Specialized equipment | Equipment-native lock settings or a compensating physical control | A lock on machines that support one, and where they do not, a documented physical measure such as positioning or enclosure to satisfy the concealment intent. |
The caveat is that the office case and the floor case are different problems. On the office desktop the native settings satisfy the control outright; on the shared floor terminal the control is only sustainable if reauthentication is fast enough to accept, so the tooling that matters most is often the badge reader rather than the timeout. The assessor tests objectives [b] and [c] by letting a machine idle and observing whether it locks and hides its content, including on representative floor systems.
6Evidence
The satisfied version of 3.1.10 shows the defined period, the enforced lock, and the concealed display across the range of systems.
| Evidence | What it demonstrates |
|---|---|
| Session-lock policy configuration | Objectives [a], [b]. The defined inactivity period and the lock-on-timeout setting. |
| Pattern-hiding lock screen | Objective [c]. The lock screen concealing prior content, shown by screenshot or observation. |
| Group Policy enforcement report | Objective [b]. The lock applied across domain-joined systems. |
| Standalone and specialized system configuration | Objectives [b], [c]. The lock, or a documented compensating control, on machines outside Group Policy. |
| Floor reauthentication method | Supporting. The badge or switching approach that keeps the lock sustainable on shared terminals. |
The evidence should demonstrate the lock on the systems most likely to display CUI, which on a manufacturing floor means the terminals and specialized interfaces rather than only the office desktops. Observation is the strongest evidence here, since letting a representative machine idle and watching it lock and conceal its content demonstrates all three objectives at once.
The floor terminal is the real question
Session lock is trivial on the office desktop and genuinely hard on the shared shop-floor terminal, where the honest answer is a fast reauthentication method rather than a disabled lock. Working out a locking approach the floor will actually keep, and covering the standalone and specialized machines, is part of the onsite readiness work this practice does.
Start CMMC Readiness or call 802-335-26627Sources
- NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.1.10. csrc.nist.gov
- NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.1.10[a] through 3.1.10[c]. csrc.nist.gov
- 32 CFR 170.21, Plan of Action and Milestones Requirements, governing which requirements may remain open at a Level 2 assessment. ecfr.gov