4.028 - The amount of idle time required before suspending a session must be properly set.

Information

Open sessions can increase the avenues of attack on a system. This setting is used to control when a computer disconnects an inactive SMB session. If client activity resumes, the session is automatically re-established. This protects critical and sensitive network data from exposure to unauthorized personnel with physical access to the computer.

Solution

Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> 'Microsoft Network Server: Amount of idle time required before suspending session' to '15' minutes or less.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Windows_2008_MS_V6R46_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-12, CAT|III, CCI|CCI-001133, CCI|CCI-002361, CSCv6|3, CSCv6|16.4, Rule-ID|SV-29226r2_rule, STIG-ID|4.028, Vuln-ID|V-1174

Plugin: Windows

Control ID: eeb1963790cee99d064f692140303baf7e864acab49cec77af5d2566ba45d4b0