Session Timeout
V7.3.1
Verify that there is an inactivity timeout such that re-authentication is enforced according to risk analysis and documented security decisions.
Required for Level 2 and 3
Related CAPEC™ Requirements
V7.3.2
Verify that there is an absolute maximum session lifetime such that re-authentication is enforced according to risk analysis and documented security decisions.
Required for Level 2 and 3
Related CAPEC™ Requirements
CAPEC™ (3.9): 195, 21, 464, 465, 510, 543, 593, 98
Disclaimer
Credit via OWASP ASVS.For more information visit: The OWASP ASVS Project or Github respository.. OWASP ASVS is under the Creative Commons Attribution-Share Alike v4.0 license.