1.4.1 Ensure 'Idle timeout' is less than or equal to 10 minutes for device management

Information

Set the Idle Timeout value for device management to 10 minutes or less to automatically close inactive sessions.
Rationale:
An unattended computer with an open administrative session to the device could allow an unauthorized user access to the firewall's management interface.

Solution

Navigate to Device > Setup > Management > Authentication Settings.
Set Idle Timeout to less than or equal to 10.
or
To remediate this setting, execute the following CLI command:
username@hostname#set deviceconfig setting management idle-timeout <value>
Default Value:
Not configured

See Also

https://workbench.cisecurity.org/files/1780

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-12, CSCv6|16.4

Plugin: Palo_Alto

Control ID: f8964058c3779164de0bf5a13c813720ebfdab221f5a82beb06c71c53e185b03