SV-222387r508029_rule
V-222387
SRG-APP-000001
APSC-DV-000010
CAT II
10
Design and configure the application to specify the number of logon sessions that are allowed per user.
For production environments; Review the system documentation, identify the number of application user logon sessions allowed per user, identify the methods utilized for user session management or have application administrator describe how the application implements user session management.
Utilize the management interface that is used to set the user session values, or examine configuration files in order to review user session configuration settings.
Ensure the number of sessions allowed per user is specified in accordance with the organizational requirements.
For development environments; have the developer provide design documentation or demonstrate how the application is designed to limit the number of simultaneous user logon sessions.
If the application is not configured to limit the number of logon sessions per user as defined by the organization, this is a finding.
V-222387
False
APSC-DV-000010
For production environments; Review the system documentation, identify the number of application user logon sessions allowed per user, identify the methods utilized for user session management or have application administrator describe how the application implements user session management.
Utilize the management interface that is used to set the user session values, or examine configuration files in order to review user session configuration settings.
Ensure the number of sessions allowed per user is specified in accordance with the organizational requirements.
For development environments; have the developer provide design documentation or demonstrate how the application is designed to limit the number of simultaneous user logon sessions.
If the application is not configured to limit the number of logon sessions per user as defined by the organization, this is a finding.
M
4093