The asset owner shall have policies and procedures related to locking user screens upon user request or automatically after a configured period of inactivity unless failure to access the screen can result in a greater risk to the IACS. Re-authentication shall be required of an authorized user to unlock it.