PlumbTrackLive demoGRC Risk System

← control library

Device Lock AC-11

Access Control · Moderate baseline ✗ Not implemented

Status — program-wide

What references this control

No risks name this control in their Framework field yet.

No policies reference it yet.


Link a risk or policy to this control

Attaching adds AC-11 to the item's Framework field; the ✨ AI button suggests the best match. You can also edit the Framework field on a risk / policy directly.

Source: NIST SP 800-53 Rev.5, Access Control family NIST SP 800-53 Rev.5. The baseline shows the lowest SP 800-53B baseline (Low / Moderate / High) this control appears in NIST SP 800-53B.

Control guide — plain-English, per NIST SP 800-53

AC-11 (Device Lock) is about locking a session when a person steps away, so an unattended screen or shell can’t be used by whoever walks up next. The system either locks itself after a set period of inactivity, or the user locks it on demand before leaving, and getting back in requires signing in again. It is a technical Access Control that appears in the Moderate baseline, where it also carries the enhancement AC-11(1) (Pattern-Hiding Displays).

What good looks like

Framework mapping

How to move it toward Implemented