STIGUI
V-282382CAT II — Medium severitySV-282382r1200126_rule

TOSS 5 must conceal via the session lock information previously visible on the display with a publicly viewable image.

Rule version TOSS-05-000277 · STIG v1 · 2026-08-20

Discussion

Setting the screensaver mode to blank-only conceals the contents of the display from passersby.

Check

To ensure the screensaver is configured to be blank, run the following command:

Note: This requirement assumes the use of the TOSS 5 default graphical user interface—the GNOME desktop environment. If the system does not have a graphical user interface installed, this requirement is not applicable.

$ gsettings get org.gnome.desktop.screensaver picture-uri 

If properly configured, the output should be "''".

To ensure that users cannot set the screensaver background, run the following:

$ grep picture-uri /etc/dconf/db/local.d/locks/* 

If properly configured, the output should be "/org/gnome/desktop/screensaver/picture-uri".

If it is not set or configured properly, this is a finding.

Fix

Edit the "dconf" settings in the /etc/dconf/db/* location.

First, add or update the [org/gnome/desktop/screensaver] section of the "/etc/dconf/db/local.d/00-security-settings" database file and add or update the following lines:

[org/gnome/desktop/screensaver] picture-uri=''

Add the following line to "/etc/dconf/db/local.d/locks/00-security-settings-lock" to prevent user modification:

/org/gnome/desktop/screensaver/picture-uri

Update the dconf system databases:

$ sudo dconf update

Identifiers

Group ID
V-282382
Group title
SRG-OS-000031-GPOS-00012
Rule ID
SV-282382r1200126_rule
Check ID
C-86943r1200124_chk
Fix ID
F-86848r1200125_fix