AC-12 Session control
Requires user sessions to be terminated automatically when organization-defined conditions or trigger events occur, such as elapsed session time or period of inactivity, rather than left open until the user chooses to cl
4
artefacts
2
held by a system
0
at each review
easy
to go live
Identity provider / directory
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Application or platform configuration showing session timeout values in force · Identity provider / directory
- Session logs demonstrating automatic termination events actually firing · Identity provider / directory
periodic reviewEvidence produced at each review
none for this control
governing documentDocuments that govern the control
- Documented list of the conditions and trigger events that force session termination · Policy repository / GRC workspace
- Design note covering how long-running or batch sessions are treated · Policy repository / GRC workspace
First move
Automate the pull from your Identity provider / directory. Scheduled export of users, roles and MFA state from the directory; access-review completion pulled from the IdP, not a spreadsheet.
Common gaps auditors find
- Termination conditions never defined, so the control has no measurable target
- Web tier enforces a timeout while the underlying API tokens remain valid for far longer
- Termination logs out the interface but leaves the server-side session or token alive
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetAC-11 Device lock · AC-14 Permitted actions without identification or authentication