Mapped to NIST 800-171 Requirement: 3.1.10
CMMC Assessment Objective: AC.L2-3.1.10[c]
What This Objective Means
This control ensures that when a session locks—whether automatically after inactivity or manually—the screen doesn’t continue displaying any sensitive content. The system must immediately display a lock screen, login prompt, or screensaver that blocks the view of CUI or system activity.
This applies to:
• Workstations and laptops
• Remote desktops
• Virtual desktops and cloud-hosted environments
• Mobile devices and tablets used to access CUI
Why It Matters
Even if access is locked, leaving CUI visible on-screen is a data exposure risk. Someone walking by or shoulder-surfing could:
• Read sensitive emails or reports
• View system configurations
• Capture data with their phone or by screenshot
Obscuring screen contents during lock protects against casual observation and opportunistic access.
How to Implement It
• Enable screensaver or lock screen functionality that hides all user data
• Require password or MFA to unlock the screen
• Set screens to:
◦ Show only a login prompt
◦ Display a generic company or system use message
• Test behavior after lockout to ensure CUI is no longer visible
• Configure mobile devices to automatically dim or lock displays after inactivity
Evidence the Assessor Will Look For
• Screenshots or videos showing system behavior after lockout
• Endpoint management policies (e.g., GPO, MDM) that enable screen protection
• System documentation or user guidance explaining expected behavior
• Test results or audit findings verifying screen visibility is blocked after session lock
Common Gaps
• Lock screen enabled, but previous screen contents remain visible
• Screensaver active but doesn’t require a password to resume
• Systems where lock screen behavior varies depending on user or department
How Cuick Trac Helps
Cuick Trac protects screen-based exposure by:
• Automatically locking sessions after inactivity and obscuring all visible content
• Displaying a compliant login or system use screen with no CUI exposure
• Enforcing consistent screen lock behavior across the secure enclave
• Helping organizations document, test, and enforce display protection across their internal infrastructure
With Cuick Trac, what was once visible is hidden the moment a session locks.
Final CTA
Locking access means locking visibility.
Schedule a Cuick Trac demo and secure your screen—even when you’re away from the keyboard.