STIGhub
STIGs
RMF Controls
Compare
← SC-23 (1) — Session Authenticity
CCI-001185
Definition
Invalidate session identifiers upon user logout or other session termination.
Parent Control
SC-23 (1)
Session Authenticity
System and Communications Protection
Linked STIG Checks (25)
V-214250
CAT II
The Apache web server must invalidate session identifiers upon hosted application user logout or other session termination.
Apache Server 2.4 UNIX Server Security Technical Implementation Guide
V-214341
CAT II
The Apache web server must set an absolute timeout for sessions.
Apache Server 2.4 Windows Server Security Technical Implementation Guide
V-204958
CAT II
The ALG must invalidate session identifiers upon user logout or other session termination.
Application Layer Gateway Security Requirements Guide
V-222578
CAT I
The application must destroy the session ID value and/or cookie on logoff or browser close.
Application Security and Development Security Technical Implementation Guide
V-204763
CAT II
The application server must invalidate session identifiers upon user logout or other session termination.
Application Server Security Requirements Guide
V-237322
CAT I
The ArcGIS Server must use Windows authentication to enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies.
ArcGIS for Server 10.3 Security Technical Implementation Guide
V-237373
CAT II
The CA API Gateway must invalidate session identifiers upon user logout or other session termination.
CA API Gateway ALG Security Technical Implementation Guide
V-233606
CAT II
PostgreSQL must invalidate session identifiers upon user logout or other session termination.
Crunchy Data PostgreSQL Security Technical Implementation Guide
V-261899
CAT II
PostgreSQL must invalidate session identifiers upon user logout or other session termination.
Crunchy Data Postgres 16 Security Technical Implementation Guide
V-206565
CAT II
The DBMS must invalidate session identifiers upon user logout or other session termination.
Database Security Requirements Guide
V-259258
CAT II
The EDB Postgres Advanced Server must invalidate session identifiers upon user logout or other session termination.
EnterpriseDB Postgres Advanced Server (EPAS) Security Technical Implementation Guide
V-65235
CAT II
The DataPower Gateway must invalidate session identifiers upon user logout or other session termination.
IBM DataPower ALG Security Technical Implementation Guide
V-253706
CAT II
MariaDB must invalidate session identifiers upon user logout or other session termination.
MariaDB Enterprise 10.x Security Technical Implementation Guide
V-202075
CAT II
The network device must invalidate session identifiers upon administrator logout or other session termination.
Network Device Management Security Requirements Guide
V-219779
CAT II
The DBMS must terminate user sessions upon user logout or any other organization or policy-defined session termination events, such as idle time limit exceeded.
Oracle Database 11.2g Security Technical Implementation Guide
V-220295
CAT II
The DBMS must terminate user sessions upon user logoff or any other organization or policy-defined session termination events, such as idle time limit exceeded.
Oracle Database 12c Security Technical Implementation Guide
V-235985
CAT II
Oracle WebLogic must terminate user sessions upon user logout or any other organization- or policy-defined session termination events such as idle time limit exceeded.
Oracle WebLogic Server 12c Security Technical Implementation Guide
V-214140
CAT II
PostgreSQL must invalidate session identifiers upon user logout or other session termination.
PostgreSQL 9.x Security Technical Implementation Guide
V-234406
CAT II
The UEM server must invalidate session identifiers upon user logout or other session termination.
Unified Endpoint Management Server Security Requirements Guide
V-239846
CAT II
The vRealize Automation application must be configured to a 15 minute of less session timeout.
VMware Automation 7.x Application Security Technical Implementation Guide
V-246894
CAT II
The Horizon Connection Server must time out administrative sessions after 15 minutes or less.
VMware Horizon 7.13 Connection Server Security Technical Implementation Guide
V-239841
CAT II
The vRealize Operations server session timeout must be configured.
VMware vRealize Operations Manager 6.x Application Security Technical Implementation Guide
V-207224
CAT II
The VPN Gateway must invalidate session identifiers upon user logoff or other session termination.
Virtual Private Network (VPN) Security Requirements Guide
V-206396
CAT II
The web server must invalidate session identifiers upon hosted application user logout or other session termination.
Web Server Security Requirements Guide
V-269572
CAT I
Xylok Security Suite must expire a session upon browser closing.
Xylok Security Suite 20.x Security Technical Implementation Guide