SV-96101r1_rule
V-81387
SRG-APP-000435-AS-000163
WBSP-AS-001580
CAT III
10
From the admin console navigate to Servers >> all servers >> [web application server] >> Session management.
For every [web application server], set the "Maximum in-memory session count", "allow overflow", and "session timeout" values according to your organizational requirements.
Review System Security Plan documentation.
Identify the application load requirements defined by system owner.
Regular application user session timeout values are defined at the DoD level at 20 minutes.
An ISSO risk acceptance is required to deviate from that value.
If session timeout values are not set to "20" and an ISSO risk acceptance is provided, this is not a finding.
From the admin console, navigate to Servers >> all servers >> [web application server] >> Session management.
For every [web application server], verify maximum in-memory session count.
Verify "allow overflow" and "session timeout" are set according to application load requirements.
If they are not set according to application load requirements, this is a finding.
V-81387
False
WBSP-AS-001580
Review System Security Plan documentation.
Identify the application load requirements defined by system owner.
Regular application user session timeout values are defined at the DoD level at 20 minutes.
An ISSO risk acceptance is required to deviate from that value.
If session timeout values are not set to "20" and an ISSO risk acceptance is provided, this is not a finding.
From the admin console, navigate to Servers >> all servers >> [web application server] >> Session management.
For every [web application server], verify maximum in-memory session count.
Verify "allow overflow" and "session timeout" are set according to application load requirements.
If they are not set according to application load requirements, this is a finding.
M
3399