Audits
Settings
Links
Tenable Cloud
Tenable Community & Support
Tenable University
Theme
Light
Dark
Auto
Help
Plugins
Overview
Plugins Pipeline
Newest
Updated
Search
Nessus Families
WAS Families
NNM Families
LCE Families
Tenable OT Security Families
About Plugin Families
Release Notes
Audits
Overview
Newest
Updated
Search Audit Files
Search Items
References
Authorities
Documentation
Download All Audit Files
Policies
Overview
Search
AWS Resources
Azure Resources
GCP Resources
Kubernetes Resources
Indicators
Overview
Search
Indicators of Attack
Indicators of Exposure
CVEs
Overview
Newest
Updated
Search
Attack Path Techniques
Overview
Search
Links
Tenable Cloud
Tenable Community & Support
Tenable University
Settings
Theme
Light
Dark
Auto
Detections
Plugins
Overview
Plugins Pipeline
Release Notes
Newest
Updated
Search
Nessus Families
WAS Families
NNM Families
LCE Families
Tenable OT Security Families
About Plugin Families
Audits
Overview
Newest
Updated
Search Audit Files
Search Items
References
Authorities
Documentation
Download All Audit Files
Policies
Overview
Search
AWS Resources
Azure Resources
GCP Resources
Kubernetes Resources
Indicators
Overview
Search
Indicators of Attack
Indicators of Exposure
Analytics
CVEs
Overview
Newest
Updated
Search
Attack Path Techniques
Overview
Search
Audits
References
CCI
CCI-001185
CCI
CCI|CCI-001185
Title
Invalidate session identifiers upon user logout or other session termination.
Reference Item Details
Reference:
CCI - DISA Control Correlation Identifier
Category:
2024
Audit Items
View all Reference Audit Items
Name
Plugin
Audit Name
AS24-U1-000460 - The Apache web server must invalidate session identifiers upon hosted application user logout or other session termination.
Unix
DISA STIG Apache Server 2.4 Unix Server v3r1 Middleware
AS24-U1-000460 - The Apache web server must invalidate session identifiers upon hosted application user logout or other session termination.
Unix
DISA STIG Apache Server 2.4 Unix Server v2r3
AS24-U1-000460 - The Apache web server must invalidate session identifiers upon hosted application user logout or other session termination.
Unix
DISA STIG Apache Server 2.4 Unix Server v2r5 Middleware
AS24-U1-000460 - The Apache web server must invalidate session identifiers upon hosted application user logout or other session termination.
Unix
DISA STIG Apache Server 2.4 Unix Server v2r5
AS24-U1-000460 - The Apache web server must invalidate session identifiers upon hosted application user logout or other session termination.
Unix
DISA STIG Apache Server 2.4 Unix Server v2r7
AS24-U1-000460 - The Apache web server must invalidate session identifiers upon hosted application user logout or other session termination.
Unix
DISA STIG Apache Server 2.4 Unix Server v2r7 Middleware
AS24-U1-000460 - The Apache web server must invalidate session identifiers upon hosted application user logout or other session termination.
Unix
DISA STIG Apache Server 2.4 Unix Server v3r1
AS24-U1-000460 - The Apache web server must invalidate session identifiers upon hosted application user logout or other session termination.
Unix
DISA STIG Apache Server 2.4 Unix Server v2r6
AS24-U1-000460 - The Apache web server must invalidate session identifiers upon hosted application user logout or other session termination.
Unix
DISA STIG Apache Server 2.4 Unix Server v2r6 Middleware
AS24-U1-000460 - The Apache web server must invalidate session identifiers upon hosted application user logout or other session termination.
Unix
DISA STIG Apache Server 2.4 Unix Server v2r3 Middleware
AS24-W1-000460 - The Apache web server must invalidate session identifiers upon hosted application user logout or other session termination.
Windows
DISA STIG Apache Server 2.4 Windows Server v2r2
AS24-W1-000460 - The Apache web server must invalidate session identifiers upon hosted application user logout or other session termination.
Windows
DISA STIG Apache Server 2.4 Windows Server v3r1
AS24-W1-000460 - The Apache web server must invalidate session identifiers upon hosted application user logout or other session termination.
Windows
DISA STIG Apache Server 2.4 Windows Server v2r1
AS24-W1-000460 - The Apache web server must invalidate session identifiers upon hosted application user logout or other session termination.
Windows
DISA STIG Apache Server 2.4 Windows Server v2r3
AS24-W2-000460 - The Apache web server must invalidate session identifiers upon hosted application user logout or other session termination.
Windows
DISA STIG Apache Server 2.4 Windows Site v1r3
AS24-W2-000460 - The Apache web server must invalidate session identifiers upon hosted application user logout or other session termination.
Windows
DISA STIG Apache Server 2.4 Windows Site v2r1
EPAS-00-005200 - The EDB Postgres Advanced Server must invalidate session identifiers upon user logout or other session termination.
PostgreSQLDB
EnterpriseDB PostgreSQL Advanced Server DB v2r1
EPAS-00-005200 - The EDB Postgres Advanced Server must invalidate session identifiers upon user logout or other session termination.
PostgreSQLDB
EnterpriseDB PostgreSQL Advanced Server DB v1r1
IISW-SV-000134 - The IIS 8.5 web server must use cookies to track session state.
Windows
DISA IIS 8.5 Server v2r1
IISW-SV-000134 - The IIS 8.5 web server must use cookies to track session state.
Windows
DISA IIS 8.5 Server v2r3
IISW-SV-000134 - The IIS 8.5 web server must use cookies to track session state.
Windows
DISA IIS 8.5 Server v2r5
IISW-SV-000134 - The IIS 8.5 web server must use cookies to track session state.
Windows
DISA IIS 8.5 Server v2r6
IISW-SV-000134 - The IIS 8.5 web server must use cookies to track session state.
Windows
DISA IIS 8.5 Server v2r7
IISW-SV-000134 - The IIS 8.5 web server must use cookies to track session state.
Windows
DISA IIS 8.5 Server v1r9
MADB-10-004700 - MariaDB must invalidate session identifiers upon user logout or other session termination.
MySQLDB
DISA MariaDB Enterprise 10.x v2r1 DB
MADB-10-004700 - MariaDB must invalidate session identifiers upon user logout or other session termination.
MySQLDB
DISA MariaDB Enterprise 10.x v1r3 DB
MADB-10-004700 - MariaDB must invalidate session identifiers upon user logout or other session termination. - max_statement_time
MySQLDB
DISA MariaDB Enterprise 10.x v1r2 DB
MADB-10-004700 - MariaDB must invalidate session identifiers upon user logout or other session termination. - tcp_keepalive_interval
MySQLDB
DISA MariaDB Enterprise 10.x v1r2 DB
MADB-10-004700 - MariaDB must invalidate session identifiers upon user logout or other session termination. - tcp_keepalive_probes
MySQLDB
DISA MariaDB Enterprise 10.x v1r2 DB
MADB-10-004700 - MariaDB must invalidate session identifiers upon user logout or other session termination. - tcp_keepalive_time
MySQLDB
DISA MariaDB Enterprise 10.x v1r2 DB
MADB-10-004700 - MariaDB must invalidate session identifiers upon user logout or other session termination. - tcp_nodelay
MySQLDB
DISA MariaDB Enterprise 10.x v1r2 DB
O112-C2-017600 - The DBMS must terminate user sessions upon user logout or any other organization or policy-defined session termination events, such as idle time limit exceeded - CONNECT_TIME
OracleDB
DISA STIG Oracle 11.2g v2r3 Database
O112-C2-017600 - The DBMS must terminate user sessions upon user logout or any other organization or policy-defined session termination events, such as idle time limit exceeded - IDLE_TIME
OracleDB
DISA STIG Oracle 11.2g v2r3 Database
O112-C2-017600 - The DBMS must terminate user sessions upon user logout or any other organization or policy-defined session termination events, such as idle time limit exceeded - SESSIONS_PER_USER
OracleDB
DISA STIG Oracle 11.2g v2r3 Database
O112-C2-017600 - The DBMS must terminate user sessions upon user logout or any other organization or policy-defined session termination events, such as idle time limit exceeded.
OracleDB
DISA STIG Oracle 11.2g v2r4 Database
O112-C2-017600 - The DBMS must terminate user sessions upon user logout or any other organization or policy-defined session termination events, such as idle time limit exceeded.
OracleDB
DISA STIG Oracle 11.2g v2r5 Database
O121-C2-017600 - The DBMS must terminate user sessions upon user logoff or any other organization or policy-defined session termination events, such as idle time limit exceeded
OracleDB
DISA STIG Oracle 12c v2r8 Database
O121-C2-017600 - The DBMS must terminate user sessions upon user logoff or any other organization or policy-defined session termination events, such as idle time limit exceeded - CONNECT_TIME
OracleDB
DISA STIG Oracle 12c v2r6 Database
O121-C2-017600 - The DBMS must terminate user sessions upon user logoff or any other organization or policy-defined session termination events, such as idle time limit exceeded - SESSIONS_PER_USER
OracleDB
DISA STIG Oracle 12c v2r6 Database
O121-C2-017600 - The DBMS must terminate user sessions upon user logoff or any other organization or policy-defined session termination events, such as idle time limit exceeded.
OracleDB
DISA STIG Oracle 12c v2r6 Database
O121-C2-017600 - The DBMS must terminate user sessions upon user logoff or any other organization or policy-defined session termination events, such as idle time limit exceeded.
OracleDB
DISA STIG Oracle 12c v2r9 Database
O121-C2-017600 - The DBMS must terminate user sessions upon user logoff or any other organization or policy-defined session termination events, such as idle time limit exceeded.
OracleDB
DISA STIG Oracle 12c v3r1 Database
O121-C2-017600 - The DBMS must terminate user sessions upon user logoff or any other organization or policy-defined session termination events, such as idle time limit exceeded.
OracleDB
DISA STIG Oracle 12c v2r8 Database
PGS9-00-010600 - PostgreSQL must invalidate session identifiers upon user logout or other session termination - statement_timeout
PostgreSQLDB
DISA STIG PostgreSQL 9.x on RHEL DB v2r3
PGS9-00-010600 - PostgreSQL must invalidate session identifiers upon user logout or other session termination - tcp_keepalives_count
PostgreSQLDB
DISA STIG PostgreSQL 9.x on RHEL DB v2r3
PGS9-00-010600 - PostgreSQL must invalidate session identifiers upon user logout or other session termination - tcp_keepalives_idle
PostgreSQLDB
DISA STIG PostgreSQL 9.x on RHEL DB v2r3
PGS9-00-010600 - PostgreSQL must invalidate session identifiers upon user logout or other session termination - tcp_keepalives_interval
PostgreSQLDB
DISA STIG PostgreSQL 9.x on RHEL DB v2r3
PGS9-00-010600 - PostgreSQL must invalidate session identifiers upon user logout or other session termination.
PostgreSQLDB
DISA STIG PostgreSQL 9.x on RHEL DB v2r4
PGS9-00-010600 - PostgreSQL must invalidate session identifiers upon user logout or other session termination.
PostgreSQLDB
DISA STIG PostgreSQL 9.x on RHEL DB v2r5
SP13-00-000115 - SharePoint must terminate user sessions upon user logoff, and when idle time limit is exceeded.
Windows
DISA STIG SharePoint 2013 v1r8