4.028 - The amount of idle time required before suspending a session must be properly set.

Information

Open sessions can increase the avenues of attack on a system. This setting is used to control when a computer disconnects an inactive SMB session. If client activity resumes, the session is automatically re-established. This protects critical and sensitive network data from exposure to unauthorized personnel with physical access to the computer.

Solution

Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> 'Microsoft Network Server- Amount of idle time required before suspending session' to '15' minutes or less.

See Also

http://iasecontent.disa.mil/stigs/zip/Oct2016/U_Windows_Vista_V6R41_STIG.zip

Item Details

Category: ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-12, 800-53|SC-10, CAT|III, CCI|CCI-001133, CCI|CCI-002361, Rule-ID|SV-29225r2_rule, STIG-ID|4.028, Vuln-ID|V-1174

Plugin: Windows

Control ID: 0d5adc8ff0cd2ec39e7f825064d2136e8eefdc92872dec32d25dd8bb38e274c7