This stems from the STIG requirement for screen for virtual terminal locking per this mailing list discussion. Basically, if there is a reason that one technology is chosen over another, then there should be an actionable cross-reference between the two policies.
Additionally, any additional configuration information from the other standard (in this case the Common Criteria Protection Profile) should be inherited by the referencing standard for a complete configuration solution.
Description of problem:
This stems from the STIG requirement for
screen
for virtual terminal locking per this mailing list discussion. Basically, if there is a reason that one technology is chosen over another, then there should be an actionable cross-reference between the two policies.Additionally, any additional configuration information from the other standard (in this case the Common Criteria Protection Profile) should be inherited by the referencing standard for a complete configuration solution.