Diff: FAQ #1147
What is the purpose of requiring consoles/PCs to become ?locked? after 15 minutes of idle time, per PCI DSS requirement 8.5.15?
Earlier Version
2014-07-07 13:52:00 UTC
2014-07-07 13:52:00 UTC
Later Version
2025-11-17 08:31:21 UTC
2025-11-17 08:31:21 UTC
Removed
Added
The intent of this requirement is to prevent an unauthorized person from using an unattended console/PC to gain access to the user’'s computer and accounts, and potentially to the company’'s network.
Thisdoes notrequirement is not intended to prevent legitimate activities from being performed while the console/PC is unattended. For example, if a user needs to run a program from an unattended computer, they can login to the computer to initiate the program, and then “"lock”" the computer so that no one else can use their login while the computer is unattended. An example of how to meet this requirement includes configuring an automated screensaver to launch whenever the console has been idle for 15 minutes, and requiresing the logged-in user to enter their password in order to unlock the screere-authenticate to re-activate the terminal or session.
Note:For critical sRequirement 8.2.8 is not intended to applystems (for example, s to user accounts on point-of-sale terminals that have access to onlystems that perform security functions or have access to sensitive data), it may one card numbe appropriate to reduce the time that the system is idle before the console is lockedr at a time to facilitate a single transaction.
(Note: PCI DSS Requirement numbers refer to PCI DSS version 3)
This
Note:
(Note: PCI DSS Requirement numbers refer to PCI DSS version 3)