3.8 ASP Session Object Timeout (AspSessionTimeout) - 'Global Setting - AspSessionTimeout <= 10'

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Setting the AspSessionTimeout property will prevent session objects from using extraneously consuming memory resources as well as minimizing session replay attacks.

Solution

Make sure 'ASP Session Object Timeout (AspSessionTimeout)' is set from a minimum of 1 minute to a maximum of 10 minutes.

See Also

https://workbench.cisecurity.org/files/657

Item Details

Audit Name: CIS IIS 6.0 v1.0.0

Category: ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-12, 800-53|SC-5, CSCv6|16.4

Plugin: Windows

Control ID: 42f4336c5205057b6dc289f80c37ce5263009040936a02b2317966a1a13e39b5