Back to catalog
NET-09.1NETNetwork Security
Invalidate Session Identifiers at Logout
Description
Automated mechanisms exist to invalidate session identifiers upon user logout or other session termination.
Cross-Mappings
30 paths across 3 frameworks
Cross-Mappings
NIST 800-531 mapping
SC-23(1)
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
CCI1 mapping
CCI-001185
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
STIG18 mappings
SV-202075r1043179_ruleThe network device must invalidate session identifiers upon administrator logout or other session termination.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · V5R3 · disa_xccdf · related
SV-204763r1043179_ruleThe application server must invalidate session identifiers upon user logout or other session termination.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · 4 · disa_xccdf · related
SV-204958r396009_ruleThe ALG must invalidate session identifiers upon user logout or other session termination.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · 2 · disa_xccdf · related
SV-206396r1043179_ruleThe web server must invalidate session identifiers upon hosted application user logout or other session termination.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · 4 · disa_xccdf · related
SV-206565r1043179_ruleThe DBMS must invalidate session identifiers upon user logout or other session termination.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · 4 · disa_xccdf · related
SV-207224r608988_ruleThe VPN Gateway must invalidate session identifiers upon user logoff or other session termination.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · 3 · disa_xccdf · related
SV-214250r1043179_ruleThe Apache web server must invalidate session identifiers upon hosted application user logout or other session termination.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · 3 · disa_xccdf · related
SV-214331r1043179_ruleThe Apache web server must invalidate session identifiers upon hosted application user logout or other session termination.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · 3 · disa_xccdf · related
SV-214375r1067795_ruleThe Apache web server must invalidate session identifiers upon hosted application user logout or other session termination.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · 2 · disa_xccdf · related
SV-222578r1043179_ruleThe application must destroy the session ID value and/or cookie on logoff or browser close.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · 6 · disa_xccdf · related
+8 more (top 10 by confidence shown)
Control mappings provided by the Secure Controls Framework (SCF).
SCF
Powered by the Secure Controls Framework
The control catalog, cross-mappings, and STRM relationship data shown here are provided by the Secure Controls Framework (SCF), 2026.2. Every mapping is credited to SCF as the methodology, with the SCF reference and version stored alongside it.
© SCF Council, LLC. Secure Controls Framework content is free and shown here with attribution. securecontrolsframework.com · About SCF on STIGViewer