IAM-16—Session Timeout
>Control Description
Information systems are configured to terminate inactive sessions after 15 minutes or when the user terminates the session.
Theme
Technology
Type
Preventive
Policy/Standard
Access Management Procedure>Implementation Guidance
1. Ensure that information systems are configured to terminate inactive sessions after 15 minutes or when the user terminates the session.
>Testing Procedure
1. Inspect Organization's Logical Access Account Standard to determine whether the requirements for access reviews were defined. 2. Inspect the server samples from the service team. 3. Select the sample from the listing and inspect session timeout configuration
>Audit Artifacts
E-IAM-01
E-IAM-23
>Framework Mappings
Cross-framework mappings provided by Adobe CCF Open Source under Creative Commons License.
Ask AI
Configure your API key to use AI features.