Session Management Documentation
V7.1.1
Verify that the user's session inactivity timeout and absolute maximum session lifetime are documented, are appropriate in combination with other controls, and that the documentation includes justification for any deviations from NIST SP 800-63B re-authentication requirements.
Required for Level 2 and 3
Related CAPEC™ Requirements
V7.1.2
Verify that the documentation defines how many concurrent (parallel) sessions are allowed for one account as well as the intended behaviors and actions to be taken when the maximum number of active sessions is reached.
Required for Level 2 and 3
Related CAPEC™ Requirements
CAPEC™ (3.9): 195, 21, 464, 465, 510, 543, 593, 98
V7.1.3
Verify that all systems that create and manage user sessions as part of a federated identity management ecosystem (such as SSO systems) are documented along with controls to coordinate session lifetimes, termination, and any other conditions that require re-authentication.
Required for Level 2 and 3
Related CAPEC™ Requirements
CAPEC™ (3.9): 195, 21, 31, 464, 465, 510, 543, 593, 98
Disclaimer
Credit via OWASP ASVS.For more information visit: The OWASP ASVS Project or Github respository.. OWASP ASVS is under the Creative Commons Attribution-Share Alike v4.0 license.