3.8 ASP Session Object Timeout (AspSessionTimeout) - 'Global Setting - AspSessionTimeout <= 10'

Information

Setting the AspSessionTimeout property will prevent session objects from using extraneously consuming memory resources as well as minimizing session replay attacks.

Solution

Make sure 'ASP Session Object Timeout (AspSessionTimeout)' is set from a minimum of 1 minute to a maximum of 10 minutes.

See Also

https://workbench.cisecurity.org/files/657

Item Details

Audit Name: CIS IIS 6.0 v1.0.0

Category: ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-12, 800-53|SC-5, CSCv6|16.4

Plugin: Windows

Control ID: 42f4336c5205057b6dc289f80c37ce5263009040936a02b2317966a1a13e39b5