800-53|AC-10

Title

CONCURRENT SESSION CONTROL

Description

The information system limits the number of concurrent sessions for each [Assignment: organization-defined account and/or account type] to [Assignment: organization-defined number].

Supplemental

Organizations may define the maximum number of concurrent sessions for information system accounts globally, by account type (e.g., privileged user, non-privileged user, domain, specific application), by account, or a combination. For example, organizations may limit the number of concurrent sessions for system administrators or individuals working in particularly sensitive domains or mission-critical applications. This control addresses concurrent sessions for information system accounts and does not address concurrent sessions by single users via multiple system accounts.

Reference Item Details

Category: ACCESS CONTROL

Family: ACCESS CONTROL

Priority: P3

Baseline Impact: HIGH

Audit Items

View all Reference Audit Items

NamePluginAudit Name
1.1 CISC-ND-000010CiscoCIS Cisco IOS Switch NDM STIG v1.1.0 CAT II
1.1 CISC-ND-000010CiscoCIS Cisco IOS XE Switch NDM STIG v1.1.0 CAT II
1.1 CISC-ND-000010CiscoCIS Cisco IOS XR Router NDM STIG v1.0.0 CAT II
1.1 CISC-ND-000010CiscoCIS Cisco NX OS Switch NDM STIG v1.0.0 CAT II
1.1 IBMW-LS-000010UnixCIS IBM WebSphere Liberty Server STIG v1.0.0 CAT II
1.1 O19C-00-000100OracleDBCIS Oracle Database 19c STIG v1.1.0 CAT II OracleDB
1.1 SQLI-22-003600MS_SQLDBCIS Microsoft SQL Server 2022 Instance STIG v1.0.0 CAT II MS_SQLDB
1.1 VCEM-80-000001UnixCIS VMware vSphere 8.0 vCenter Appliance ESX Agent Manager EAM STIG v1.0.0 CAT II
1.1 VCLD-80-000001UnixCIS VMware vSphere 8.0 vCenter Appliance Management Interface VAMI STIG v1.0.0 CAT II
1.1 VCLU-80-000001UnixCIS VMware vSphere 8.0 vCenter Appliance Lookup Service STIG v1.0.0 CAT II
1.1 VCPF-80-000001UnixCIS VMware vSphere 8.0 vCenter Appliance Perfcharts STIG v1.0.0 CAT II
1.1 VCST-80-000001UnixCIS VMware vSphere 8.0 vCenter Appliance Secure Token Service STS STIG v1.0.0 CAT II
1.1 VCUI-80-000001UnixCIS VMware vSphere 8.0 vCenter Appliance User Interface UI STIG v1.0.0 CAT II
1.2 O19C-00-000200UnixCIS Oracle Database 19c STIG v1.1.0 CAT II Unix
1.2.9 Set 'http Secure-server' limitCiscoCIS Cisco IOS XE 17.x v2.2.1 L1
1.2.10 Set 'http Secure-server' limitCiscoCIS Cisco IOS XE 16.x v2.2.0 L1
1.3 PHTN-40-000007UnixCIS VMware vSphere 8.0 vCenter Appliance Photon OS 4.0 STIG v1.0.0 CAT III
1.5.5 Ensure number of concurrent sessions is limitedUnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
1.5.5 Ensure number of concurrent sessions is limitedUnixCIS Amazon Linux 2 STIG v2.0.1 STIG
1.15 VCST-80-000125UnixCIS VMware vSphere 8.0 vCenter Appliance Secure Token Service STS STIG v1.0.0 CAT II
1.16 VCEM-80-000125UnixCIS VMware vSphere 8.0 vCenter Appliance ESX Agent Manager EAM STIG v1.0.0 CAT II
1.16 VCLU-80-000125UnixCIS VMware vSphere 8.0 vCenter Appliance Lookup Service STIG v1.0.0 CAT II
1.16 VCPF-80-000125UnixCIS VMware vSphere 8.0 vCenter Appliance Perfcharts STIG v1.0.0 CAT II
1.16 VCST-80-000126UnixCIS VMware vSphere 8.0 vCenter Appliance Secure Token Service STS STIG v1.0.0 CAT II
1.16 VCUI-80-000125UnixCIS VMware vSphere 8.0 vCenter Appliance User Interface UI STIG v1.0.0 CAT II
1.17 VCEM-80-000126UnixCIS VMware vSphere 8.0 vCenter Appliance ESX Agent Manager EAM STIG v1.0.0 CAT II
1.17 VCLU-80-000126UnixCIS VMware vSphere 8.0 vCenter Appliance Lookup Service STIG v1.0.0 CAT II
1.17 VCPF-80-000126UnixCIS VMware vSphere 8.0 vCenter Appliance Perfcharts STIG v1.0.0 CAT II
1.17 VCUI-80-000126UnixCIS VMware vSphere 8.0 vCenter Appliance User Interface UI STIG v1.0.0 CAT II
1.34 UBTU-24-200000UnixCIS Ubuntu Linux 24.04 LTS STIG v1.0.0 CAT III
1.70 SLES-15-020020UnixCIS SUSE Linux Enterprise Server 15 STIG v1.0.0 CAT III
1.82 UBTU-22-412020UnixCIS Ubuntu Linux 22.04 LTS STIG v1.0.0 CAT III
1.115 SOL-11.1-040500UnixCIS Solaris 11 X86 STIG v1.0.0 CAT III
1.117 SOL-11.1-040500UnixCIS Solaris 11 SPARC STIG v1.0.0 CAT III
1.148 AZLX-23-002395UnixCIS Amazon Linux 2023 STIG v1.0.0 CAT III
1.150 OL08-00-020024UnixCIS Oracle Linux 8 STIG v1.0.0 CAT III
1.272 RHEL-10-600475UnixCIS Red Hat Enterprise Linux 10 STIG v1.0.0 CAT III
1.289 RHEL-09-412040UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT III
3.1.11 Set maximum connection limits - MAX_CONNECTIONSUnixCIS IBM DB2 v10 v1.1.0 Linux OS Level 1
3.1.11 Set maximum connection limits - MAX_CONNECTIONSUnixCIS IBM DB2 v10 v1.1.0 Linux OS Level 2
3.1.11 Set maximum connection limits - MAX_COORDAGENTSUnixCIS IBM DB2 v10 v1.1.0 Linux OS Level 1
3.1.11 Set maximum connection limits - MAX_COORDAGENTSUnixCIS IBM DB2 v10 v1.1.0 Linux OS Level 2
3.1.11 Set maximum connection limits - MAXAPPLSUnixCIS IBM DB2 v10 v1.1.0 Linux OS Level 1
3.1.11 Set maximum connection limits - MAXAPPLSUnixCIS IBM DB2 v10 v1.1.0 Linux OS Level 2
3.1.14 Set maximum connection limits - 'max_connections <= 100'UnixCIS IBM DB2 OS L2 v1.2.0
3.1.14 Set maximum connection limits - 'max_coordagents <= 100'UnixCIS IBM DB2 OS L2 v1.2.0
3.1.14 Set maximum connection limits - 'maxappls <= 99'UnixCIS IBM DB2 OS L2 v1.2.0
3.1.14 Set maximum connection limits - MAX_CONNECTIONSIBM_DB2DBCIS IBM DB2 9 Benchmark v3.0.1 Level 2 DB
3.1.14 Set maximum connection limits - MAX_CONNECTIONSIBM_DB2DBCIS IBM DB2 9 Benchmark v3.0.1 Level 1 DB
3.1.14 Set maximum connection limits - MAX_COORDAGENTSIBM_DB2DBCIS IBM DB2 9 Benchmark v3.0.1 Level 1 DB