SV-222390r508029_rule
V-222390
SRG-APP-000295
APSC-DV-000080
CAT II
10
Design and configure the application to terminate the admin users session after 10 minutes of inactivity.
Ask the application representative to demonstrate the application configuration setting where the idle time out value is defined for admin users.
Alternatively, logon with an admin user account and let the session sit idle for 10 minutes.
Attempt to access the application after 10 minutes of inactivity.
If the configuration setting is not set to time out admin user sessions after 10 minutes of inactivity, or if the session used for testing does not time out after 10 minutes of inactivity, this is a finding.
V-222390
False
APSC-DV-000080
Ask the application representative to demonstrate the application configuration setting where the idle time out value is defined for admin users.
Alternatively, logon with an admin user account and let the session sit idle for 10 minutes.
Attempt to access the application after 10 minutes of inactivity.
If the configuration setting is not set to time out admin user sessions after 10 minutes of inactivity, or if the session used for testing does not time out after 10 minutes of inactivity, this is a finding.
M
4093