800-53|AC-12(1)

Title

USER-INITIATED LOGOUTS / MESSAGE DISPLAYS

Description

The information system:

Supplemental

Information resources to which users gain access via authentication include, for example, local workstations, databases, and password-protected websites/web-based services. Logout messages for web page access, for example, can be displayed after authenticated sessions have been terminated. However, for some types of interactive sessions including, for example, file transfer protocol (FTP) sessions, information systems typically send logout messages as final messages prior to terminating sessions.

Reference Item Details

Category: ACCESS CONTROL

Parent Title: SESSION TERMINATION

Family: ACCESS CONTROL

Audit Items

View all Reference Audit Items

NamePluginAudit Name
AIX7-00-002128 - If bash is used, AIX must display logout messages.UnixDISA STIG AIX 7.x v3r1
AIX7-00-002129 - If Bourne / ksh shell is used, AIX must display logout messages.UnixDISA STIG AIX 7.x v3r1
AIX7-00-002130 - If csh/tcsh shell is used, AIX must display logout messages.UnixDISA STIG AIX 7.x v3r1
ALMA-09-001890 - AlmaLinux OS 9 must automatically exit interactive command shell user sessions after 10 minutes of inactivity.UnixDISA CloudLinux AlmaLinux OS 9 STIG v1r1
Big Sur - Display logoff capability and message to prevent exploitationUnixNIST macOS Big Sur v1.4.0 - All Profiles
Catalina - Display logoff capability and message to prevent exploitationUnixNIST macOS Catalina v1.5.0 - All Profiles
F5BI-AP-000151 - The BIG-IP APM module access policy profile must be configured to display an explicit logoff message to users, indicating the reliable termination of authenticated communications sessions when disconnecting from virtual servers.F5DISA F5 BIG-IP Access Policy Manager STIG v2r3
F5BI-LT-000151 - The BIG-IP Core must display an explicit logoff message to users indicating the reliable termination of authenticated communications sessions when providing access to virtual servers.F5DISA F5 BIG-IP Local Traffic Manager STIG v2r3
MADB-10-006300 - MariaDB must provide logout functionality to allow the user to manually terminate a session initiated by that user.MySQLDBDISA MariaDB Enterprise 10.x v2r2 DB
Monterey - Display logoff capability and message to prevent exploitationUnixNIST macOS Monterey v1.0.0 - All Profiles