Applications requiring user access authentication must provide a logoff capability for user initiated communication session.
Overview
Finding ID
Version
Rule ID
IA Controls
Severity
V-222391
APSC-DV-000090
SV-222391r961224_rule
Medium
Description
If a user cannot explicitly end an application session, the session may remain open and be exploited by an attacker. Applications providing user access must provide the ability for users to manually terminate their sessions and log off.