STIGQter STIGQter: STIG Summary: Microsoft SharePoint 2013 Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 22 Jan 2021:

SharePoint must support the requirement to initiate a session lock after 15 minutes of system or application inactivity has transpired.

DISA Rule

SV-223238r612235_rule

Vulnerability Number

V-223238

Group Title

SRG-APP-000003

Rule Version

SP13-00-000005

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the SharePoint server to lock the session lock after 15 minutes of inactivity.

In SharePoint Central Administration, click Application Management.

On the Application Management page, in the Web Applications section, click Manage web applications.

Perform the following steps for each web application.
- Select web application.
- Select General Settings >> General Settings.
- Navigate to Web Page Security Validation.
- Set the "Security validation is:" property to On.
- Set the "Security validation expires:" property to After.
- Set the default time-out period to 15 minutes or less.
- Select OK to save settings.

Check Contents

Review the SharePoint server configuration to ensure a session lock occurs after 15 minutes of inactivity.

In SharePoint Central Administration, click Application Management.

On the Application Management page, in the Web Applications section, click Manage web applications.

Verify that each web application meets this requirement.
- Select the web application.
- Select General Settings >> General Settings.
- Navigate to the Web Page Security Validation section.
- Verify that the Security Validation is "On" and set to expire after 15 minutes or less.

If Security Validation is "Off" or if the default time-out period is not set to 15 minutes or less for any of the web applications, this is a finding.

Vulnerability Number

V-223238

Documentable

False

Rule Version

SP13-00-000005

Severity Override Guidance

Review the SharePoint server configuration to ensure a session lock occurs after 15 minutes of inactivity.

In SharePoint Central Administration, click Application Management.

On the Application Management page, in the Web Applications section, click Manage web applications.

Verify that each web application meets this requirement.
- Select the web application.
- Select General Settings >> General Settings.
- Navigate to the Web Page Security Validation section.
- Verify that the Security Validation is "On" and set to expire after 15 minutes or less.

If Security Validation is "Off" or if the default time-out period is not set to 15 minutes or less for any of the web applications, this is a finding.

Check Content Reference

M

Target Key

4096

Comments