6.5.6 (L1) Host SSH daemon, if enabled, must set a timeout interval on idle sessions

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Implementing a timeout interval on idle SSH sessions ensures that any inactive session gets disconnected after a certain period, improving the security posture. The total timeout duration is calculated by multiplying the timeout count by the idle timeout interval.

Enforcing a timeout interval on idle SSH sessions minimizes the risk of unauthorized access through forgotten or unattended sessions, thereby hardening the system services as per security best practices.

Solution

Impact:

No functional impact is reported with this control. The measure is preventive, aiming to mitigate risks associated with open, idle SSH sessions.

See Also

https://workbench.cisecurity.org/benchmarks/15784