Secure Controls Framework

1,534 controls across 34 domains

Source: SCF 2026.2About SCF
securecontrolsframework.com
Back to catalog
IAC-25IACIdentification & Authentication

Session Termination

Description

Automated mechanisms exist to log out users, both locally on the network and for remote sessions, at the end of the session or after an organization-defined period of inactivity.

Cross-Mappings

98 paths across 4 frameworks
NIST 800-531 mapping
AC-12
1.00
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
NIST 800-1711 mapping
3.1.11
1.00
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
CCI3 mappings
CCI-002254
1.00
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002360
1.00
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002361
1.00
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
STIG70 mappings
SV-203683r958636_ruleThe operating system must automatically terminate a user session after inactivity time-outs have expired or at shutdown.
1.00
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • DISA · 3 · disa_xccdf · related
SV-204777r1043182_ruleThe application server must automatically terminate a user session after organization-defined conditions or trigger events requiring a session disconnect.
1.00
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • DISA · 4 · disa_xccdf · related
SV-205055r831405_ruleThe ALG providing user access control intermediary services must automatically terminate a user session when organization-defined conditions or trigger events that require a session disconnect occur.
1.00
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • DISA · 2 · disa_xccdf · related
SV-205535r1043182_ruleThe Mainframe Product must automatically terminate a user session after conditions, as defined in site security plan, are met or trigger events requiring session disconnect.
1.00
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • DISA · 3 · disa_xccdf · related
SV-206414r1043182_ruleThe web server must set an absolute session timeout value of eight hours or less.
1.00
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • DISA · 4 · disa_xccdf · related
SV-206415r1043182_ruleThe web server must set an inactive timeout for sessions.
1.00
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • DISA · 4 · disa_xccdf · related
SV-206580r1043182_ruleThe DBMS must automatically terminate a user session after organization-defined conditions or trigger events requiring session disconnect.
1.00
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • DISA · 4 · disa_xccdf · related
SV-207432r958636_ruleThe VMM must automatically terminate a user session after inactivity timeouts have expired or at shutdown.
1.00
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • DISA · 2 · disa_xccdf · related
SV-213715r879673_ruleDB2 must automatically terminate a user session after organization-defined conditions or trigger events requiring session disconnect.
1.00
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • DISA · V2R1 · disa_xccdf · related
SV-214258r1043182_ruleThe Apache web server must set an inactive timeout for sessions.
1.00
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • DISA · 3 · disa_xccdf · related

+60 more (top 10 by confidence shown)

Control mappings provided by the Secure Controls Framework (SCF).

SCF

Powered by the Secure Controls Framework

The control catalog, cross-mappings, and STRM relationship data shown here are provided by the Secure Controls Framework (SCF), 2026.2. Every mapping is credited to SCF as the methodology, with the SCF reference and version stored alongside it.

© SCF Council, LLC. Secure Controls Framework content is free and shown here with attribution. securecontrolsframework.com · About SCF on STIGViewer