SV-222464r508029_rule
V-222464
SRG-APP-000505
APSC-DV-000850
CAT II
10
Configure the application or application server to record the start and end time of user session activity.
Review and monitor the application logs.
Initiate a user session and observe if the log includes a time stamp showing the start of the session.
Terminate the user session and observe if the log includes a time stamp showing the end of the session.
If the start and the end time of the session are not recorded in the logs, this is a finding.
V-222464
False
APSC-DV-000850
Review and monitor the application logs.
Initiate a user session and observe if the log includes a time stamp showing the start of the session.
Terminate the user session and observe if the log includes a time stamp showing the end of the session.
If the start and the end time of the session are not recorded in the logs, this is a finding.
M
4093