AC.L2-3.1.10[c]: Hide Information When Sessions Lock to Protect CUI on Screen

Mapped to NIST 800-171 Requirement: 3.1.10
CMMC Assessment Objective: AC.L2-3.1.10[c]

What This Objective Means
This control ensures that when a session locks—whether automatically after inactivity or manually—the screen doesn’t continue displaying any sensitive content. The system must immediately display a lock screen, login prompt, or screensaver that blocks the view of CUI or system activity.
This applies to:
• Workstations and laptops
• Remote desktops
• Virtual desktops and cloud-hosted environments
• Mobile devices and tablets used to access CUI

Why It Matters
Even if access is locked, leaving CUI visible on-screen is a data exposure risk. Someone walking by or shoulder-surfing could:
• Read sensitive emails or reports
• View system configurations
• Capture data with their phone or by screenshot
Obscuring screen contents during lock protects against casual observation and opportunistic access.

How to Implement It
• Enable screensaver or lock screen functionality that hides all user data
• Require password or MFA to unlock the screen
• Set screens to:
◦ Show only a login prompt
◦ Display a generic company or system use message
• Test behavior after lockout to ensure CUI is no longer visible
• Configure mobile devices to automatically dim or lock displays after inactivity

Evidence the Assessor Will Look For
• Screenshots or videos showing system behavior after lockout
• Endpoint management policies (e.g., GPO, MDM) that enable screen protection
• System documentation or user guidance explaining expected behavior
• Test results or audit findings verifying screen visibility is blocked after session lock

Common Gaps
• Lock screen enabled, but previous screen contents remain visible
• Screensaver active but doesn’t require a password to resume
• Systems where lock screen behavior varies depending on user or department

How Cuick Trac Helps
Cuick Trac protects screen-based exposure by:
• Automatically locking sessions after inactivity and obscuring all visible content
• Displaying a compliant login or system use screen with no CUI exposure
• Enforcing consistent screen lock behavior across the secure enclave
• Helping organizations document, test, and enforce display protection across their internal infrastructure
With Cuick Trac, what was once visible is hidden the moment a session locks.

Final CTA
Locking access means locking visibility.
Schedule a Cuick Trac demo and secure your screen—even when you’re away from the keyboard.

🍪 We Use Cookies

To enhance your experience and analyze site usage, we use cookies. By continuing to use our site, you agree to our use of cookies in accordance with our Privacy Policy.