adammontville / cis-controls-71-measures

0 stars 0 forks source link

Subcontrol 16.11 #30

Open adammontville opened 5 years ago

adammontville commented 5 years ago

Automatically lock workstation sessions after a standard period of inactivity.

Measures

M1 =# of workstation with locking enabled(Model driven, data driven)
M2 = # of workstation(Model driven, data driven)

Metrics/KEI

Enforcement Quality = M1/ M2
The same KEI can be measured with active testing

No explicit comment, other than that this is covered in most, if not all, benchmarks.

apiperCIS commented 5 years ago

Question for UNCC: The proposed measure does not take into account the time period. It should factor in more than just whether locking is enabled, but also if the locking is set for an acceptable period of time.

wmunyan commented 5 years ago

Inputs:

Operations:

Measures:

Metrics: