Diff: FAQ #1147
What is the purpose of requiring consoles/PCs to become ?locked? after 15 minutes of idle time, per PCI DSS requirement 8.5.15?
Earlier Version
Later Version
Removed
Added
The intent of this requirement is to prevent an unauthorized person from using an unattended console/PC to gain access to the user’suser's computer and accounts, and potentially to the company’scompany's network.
Thisdoesrequirement is not intended to prevent legitimate activities from being performed while the console/PC is unattended. For example, if a user needs to run a program from an unattended computer, they can login to the computer to initiate the program, and then “lock”"lock" the computer so that no one else can use their login while the computer is unattended. An example of how to meet this requirement includes configuring an automated screensaver to launch whenever the console has been idle for 15 minutes,minutes and requiresrequiring the logged-in user to enter their password in order to unlock the screen.re-authenticate to re-activate the terminal or session.
Note:For critical systems (for example, systemsRequirement 8.2.8 is not intended to apply to user accounts on point-of-sale terminals that perform security functions or have access to sensitive data), it may be appropriate to reduce theonly one card number at a time that the system is idle before the console is locked.
(Note: PCI DSS Requirement numbers refer to PCI DSS version 3)to facilitate a single transaction.
This
Note:
(Note: PCI DSS Requirement numbers refer to PCI DSS version 3)
Disclaimer: This FAQ has been processed for display on this website and may contain errors. Please check the original FAQ on the PCI SSC website for the authoritative version.