Australian Information Security Manual
Guidelines for system hardening

Australian Information Security Manual ISM-0428: Services are configured with a session lock that: - activates after a maximum of 15 minute

Services are configured with a session lock that: - activates after a maximum of 15 minutes of user inactivity, a maximum of 12 hours of overall session time or when manually activated by users - blocks access to all session content - requires users to re-authenticate using all authentication factors to unlock the session - denies users the ability to disable the session locking mechanism.

Other controls in Guidelines for system hardening

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.