SV-222445r508029_rule
V-222445
SRG-APP-000089
APSC-DV-000660
CAT II
10
Configure the application to record session timeout events in the logs.
Review the application documentation and interview the application administrator to identify log locations for application session activity.
Open the log file that tracks user session activity.
Access the application as a regular user and identify the user session within the log files.
Identify the session timeout threshold defined by the application.
Perform no action within the application in order to allow the session to timeout.
Once the session timeout threshold has been exceeded, verify the session has been terminated due to the timeout event and review the logs again to ensure the session timeout event was recorded in the logs.
If a web-based application delegates session timeout auditing to an application server, this is not a finding.
If the session timeout event is not recorded in the logs, this is a finding.
V-222445
False
APSC-DV-000660
Review the application documentation and interview the application administrator to identify log locations for application session activity.
Open the log file that tracks user session activity.
Access the application as a regular user and identify the user session within the log files.
Identify the session timeout threshold defined by the application.
Perform no action within the application in order to allow the session to timeout.
Once the session timeout threshold has been exceeded, verify the session has been terminated due to the timeout event and review the logs again to ensure the session timeout event was recorded in the logs.
If a web-based application delegates session timeout auditing to an application server, this is not a finding.
If the session timeout event is not recorded in the logs, this is a finding.
M
4093