4.4 Ensure 'Idle timeout' is less than or equal to 10 minutes for serial console sessions

Information

To set an idle timeout for serial console sessions.

Rationale:

Impact:

Indefinite or even long session timeout window increases the risk of attackers abusing abandoned sessions.

Solution

- Log in to tmsh by typing the following command:
tmsh
- To configure an automatic logout idle time for serial console sessions, use the following command :
modify /sys global-settings console-inactivity-timeout 600
- Save the change by typing the following command:
save /sys config

See Also

https://workbench.cisecurity.org/files/3587

Item Details

Category: CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

References: 800-53|CM-1, 800-53|CM-2, 800-53|CM-6, 800-53|CM-7, 800-53|CM-7(1), 800-53|CM-9, 800-53|SA-3, 800-53|SA-8, 800-53|SA-10, CSCv7|5.1

Plugin: F5

Control ID: cabd4e461cb05ee18b8e8ac67ac91b8b35abc9e8a4001c924b0584018ed1f2b3