CCI|CCI-002361

Title

Automatically terminate a user session after organization-defined conditions or trigger events requiring session disconnect.

Reference Item Details

Category: 2024

Audit Items

View all Reference Audit Items

NamePluginAudit Name
4.028 - The amount of idle time required before suspending a session must be properly set.WindowsDISA Windows Vista STIG v6r41
5.046 - Terminal Services is not configured to set a time limit for disconnected sessions.WindowsDISA Windows Vista STIG v6r41
AIX7-00-002105 - AIX must config the SSH idle timeout interval.UnixDISA STIG AIX 7.x v3r1
AIX7-00-003003 - AIX must set inactivity time-out on login sessions and terminate all login sessions after 10 minutes of inactivity.UnixDISA STIG AIX 7.x v3r1
APPL-14-000160 - The macOS system must enforce auto logout after 86400 seconds of inactivity.UnixDISA Apple macOS 14 (Sonoma) STIG v2r2
APPL-15-000160 - The macOS system must enforce auto logout after 86400 seconds of inactivity.UnixDISA Apple macOS 15 (Sequoia) STIG v1r1
AS24-W1-000640 - The Apache web server must set an absolute timeout for sessions.WindowsDISA STIG Apache Server 2.4 Windows Server v3r1
AS24-W1-000640 - The Apache web server must set an absolute timeout for sessions.WindowsDISA STIG Apache Server 2.4 Windows Server v2r3
AS24-W1-000650 - The Apache web server must set an inactive timeout for completing the TLS handshake - mod_reqtimeoutWindowsDISA STIG Apache Server 2.4 Windows Server v2r3
AS24-W1-000650 - The Apache web server must set an inactive timeout for completing the TLS handshake - mod_reqtimeoutWindowsDISA STIG Apache Server 2.4 Windows Server v3r1
AS24-W1-000650 - The Apache web server must set an inactive timeout for completing the TLS handshake - RequestReadTimeoutWindowsDISA STIG Apache Server 2.4 Windows Server v3r1
AS24-W1-000650 - The Apache web server must set an inactive timeout for completing the TLS handshake - RequestReadTimeoutWindowsDISA STIG Apache Server 2.4 Windows Server v2r3
AS24-W2-000640 - The Apache web server must set an absolute timeout for sessions.WindowsDISA STIG Apache Server 2.4 Windows Site v2r1
Big Sur - Enforce Auto Logout After 24 Hours of InactivityUnixNIST macOS Big Sur v1.4.0 - 800-171
Big Sur - Enforce Auto Logout After 24 Hours of InactivityUnixNIST macOS Big Sur v1.4.0 - 800-53r5 Moderate
Big Sur - Enforce Auto Logout After 24 Hours of InactivityUnixNIST macOS Big Sur v1.4.0 - 800-53r4 High
Big Sur - Enforce Auto Logout After 24 Hours of InactivityUnixNIST macOS Big Sur v1.4.0 - All Profiles
Big Sur - Enforce Auto Logout After 24 Hours of InactivityUnixNIST macOS Big Sur v1.4.0 - CNSSI 1253
Big Sur - Enforce Auto Logout After 24 Hours of InactivityUnixNIST macOS Big Sur v1.4.0 - 800-53r4 Moderate
Big Sur - Enforce Auto Logout After 24 Hours of InactivityUnixNIST macOS Big Sur v1.4.0 - 800-53r5 High
Catalina - Enforce Auto Logout After 24 Hours of InactivityUnixNIST macOS Catalina v1.5.0 - 800-53r5 Moderate
Catalina - Enforce Auto Logout After 24 Hours of InactivityUnixNIST macOS Catalina v1.5.0 - All Profiles
Catalina - Enforce Auto Logout After 24 Hours of InactivityUnixNIST macOS Catalina v1.5.0 - 800-53r5 High
Catalina - Enforce Auto Logout After 24 Hours of InactivityUnixNIST macOS Catalina v1.5.0 - CNSSI 1253
Catalina - Enforce Auto Logout After 24 Hours of InactivityUnixNIST macOS Catalina v1.5.0 - 800-171
Catalina - Enforce Auto Logout After 24 Hours of InactivityUnixNIST macOS Catalina v1.5.0 - 800-53r4 High
Catalina - Enforce Auto Logout After 24 Hours of InactivityUnixNIST macOS Catalina v1.5.0 - 800-53r4 Moderate
EP11-00-006700 - The EDB Postgres Advanced Server must automatically terminate a user session after organization-defined conditions or trigger events requiring session disconnect.PostgreSQLDBEDB PostgreSQL Advanced Server v11 DB Audit v2r4
EPAS-00-006700 - The EDB Postgres Advanced Server must automatically terminate a user session after organization-defined conditions or trigger events requiring session disconnect.PostgreSQLDBEnterpriseDB PostgreSQL Advanced Server DB v2r1
ESXI-06-100043 - The VMM must automatically terminate a user session after inactivity timeouts have expired or at shutdown.VMwareDISA STIG VMware vSphere 6.x ESXi v1r5
EX19-ED-000159 - Exchange must limit the Receive connector timeout.WindowsDISA Microsoft Exchange 2019 Edge Server STIG v2r1
F5BI-AP-000147 - The BIG-IP APM module access policy profile must be configured to automatically terminate user sessions for users connected to virtual servers when organization-defined conditions or trigger events occur that require a session disconnect.F5DISA F5 BIG-IP Access Policy Manager STIG v2r3
JUSX-VN-000002 - The Juniper SRX Services Gateway VPN must renegotiate the IPsec security association after 8 hours or less.JuniperDISA Juniper SRX Services Gateway VPN v3r1
Monterey - Enforce Auto Logout After 24 Hours of InactivityUnixNIST macOS Monterey v1.0.0 - CNSSI 1253
Monterey - Enforce Auto Logout After 24 Hours of InactivityUnixNIST macOS Monterey v1.0.0 - 800-171
Monterey - Enforce Auto Logout After 24 Hours of InactivityUnixNIST macOS Monterey v1.0.0 - 800-53r5 High
Monterey - Enforce Auto Logout After 24 Hours of InactivityUnixNIST macOS Monterey v1.0.0 - All Profiles
Monterey - Enforce Auto Logout After 24 Hours of InactivityUnixNIST macOS Monterey v1.0.0 - 800-53r4 High
Monterey - Enforce Auto Logout After 24 Hours of InactivityUnixNIST macOS Monterey v1.0.0 - 800-53r4 Moderate
Monterey - Enforce Auto Logout After 24 Hours of InactivityUnixNIST macOS Monterey v1.0.0 - 800-53r5 Moderate
PHTN-30-000005 - The Photon operating system must set a session inactivity timeout of 15 minutes or less.UnixDISA STIG VMware vSphere 7.0 Photon OS v1r3
PHTN-40-000093 The operating system must automatically terminate a user session after inactivity time-outs have expired.UnixDISA VMware vSphere 8.0 vCenter Appliance Photon OS 4.0 STIG v2r1
PHTN-67-000005 - The Photon operating system must set a session inactivity timeout of 15 minutes or less - durationUnixDISA STIG VMware vSphere 6.7 Photon OS v1r6
PHTN-67-000005 - The Photon operating system must set a session inactivity timeout of 15 minutes or less - exportUnixDISA STIG VMware vSphere 6.7 Photon OS v1r6
PHTN-67-000005 - The Photon operating system must set a session inactivity timeout of 15 minutes or less - mesgUnixDISA STIG VMware vSphere 6.7 Photon OS v1r6
PHTN-67-000005 - The Photon operating system must set a session inactivity timeout of 15 minutes or less - readonlyUnixDISA STIG VMware vSphere 6.7 Photon OS v1r6
PHTN-67-000054 - The Photon operating system must set an inactivity timeout value for non-interactive sessions - durationUnixDISA STIG VMware vSphere 6.7 Photon OS v1r6
PHTN-67-000054 - The Photon operating system must set an inactivity timeout value for non-interactive sessions - exportUnixDISA STIG VMware vSphere 6.7 Photon OS v1r6
PHTN-67-000054 - The Photon operating system must set an inactivity timeout value for non-interactive sessions - readonlyUnixDISA STIG VMware vSphere 6.7 Photon OS v1r6
PPS9-00-006700 - The EDB Postgres Advanced Server must automatically terminate a user session after organization-defined conditions or trigger events requiring session disconnect.PostgreSQLDBEDB PostgreSQL Advanced Server DB Audit v2r3