SV-70275r2_rule
V-56021
SRG-APP-000220-WSR-000201
SRG-APP-000220-WSR-000201
CAT II
10
Configure the web server to invalidate session identifiers when a session is terminated.
Review the web server documentation and deployed configuration to verify that the web server is configured to invalidate session identifiers when a session is terminated.
If the web server does not invalidate session identifiers when a session is terminated, this is a finding.
V-56021
False
SRG-APP-000220-WSR-000201
Review the web server documentation and deployed configuration to verify that the web server is configured to invalidate session identifiers when a session is terminated.
If the web server does not invalidate session identifiers when a session is terminated, this is a finding.
M
2557