Back to catalog
NET-09.2NETNetwork Security
Unique System-Generated Session Identifiers
Description
Automated mechanisms exist to generate and recognize unique session identifiers for each session.
Cross-Mappings
123 paths across 3 frameworks
Cross-Mappings
NIST 800-531 mapping
SC-23(3)
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
CCI3 mappings
CCI-001188
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001189
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001664
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
STIG84 mappings
SV-202076r1043180_ruleThe network device must recognize only system-generated session identifiers.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · V5R3 · disa_xccdf · related
SV-202077r1043181_ruleThe network device must generate unique session identifiers using a FIPS 140-2 approved random number generator.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · V5R3 · disa_xccdf · related
SV-204764r1043180_ruleThe application server must generate a unique session identifier for each session.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · 4 · disa_xccdf · related
SV-204765r1043180_ruleThe application server must recognize only system-generated session identifiers.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · 4 · disa_xccdf · related
SV-204766r1043181_ruleThe application server must generate a unique session identifier using a FIPS 140-2 approved random number generator.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · 4 · disa_xccdf · related
SV-204959r396012_ruleThe ALG must recognize only system-generated session identifiers.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · 2 · disa_xccdf · related
SV-204960r396015_ruleThe ALG must generate unique session identifiers using a FIPS 140-2 approved random number generator.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · 2 · disa_xccdf · related
SV-206397r1043180_ruleCookies exchanged between the web server and client, such as session cookies, must have security settings that disallow cookie access outside the originating web server and hosted application.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · 4 · disa_xccdf · related
SV-206398r1043180_ruleThe web server must accept only system-generated session identifiers.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · 4 · disa_xccdf · related
SV-206399r1043181_ruleThe web server must generate a unique session identifier for each session using a FIPS 140-2 approved random number generator.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · 4 · disa_xccdf · related
+74 more (top 10 by confidence shown)
Control mappings provided by the Secure Controls Framework (SCF).
SCF
Powered by the Secure Controls Framework
The control catalog, cross-mappings, and STRM relationship data shown here are provided by the Secure Controls Framework (SCF), 2026.2. Every mapping is credited to SCF as the methodology, with the SCF reference and version stored alongside it.
© SCF Council, LLC. Secure Controls Framework content is free and shown here with attribution. securecontrolsframework.com · About SCF on STIGViewer