8.2.8 Session idle timeout
If a user session has been idle for more than 15 minutes, the user is required to re-authenticate to re-activate the session.
5
artefacts
4
held by a system
0
at each review
easy
to go live
Cloud console / configuration management
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- System and application configuration showing 15 minute timeout · Cloud console / configuration management
- Sample test logs demonstrating session lock · SIEM / log platform
- Group policy or MDM settings export · Endpoint management (MDM / EDR)
- Configuration baseline document · Cloud console / configuration management
periodic reviewEvidence produced at each review
none for this control
governing documentDocuments that govern the control
- Exception inventory with compensating controls · Policy repository / GRC workspace
First move
Automate the pull from your Cloud console / configuration management. Configuration snapshots and change history from the cloud console or IaC repository, diffed against the baseline.
Common gaps auditors find
- Timeout exceeds 15 minutes
- Workstations excluded
- Test evidence missing
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheet8.2.7 Third-party access managed · 8.3.1 All user access to system components for users and administrators is authenticated via at least one of the following authentication factors: • Something you know, such as a password or passphrase. • Something you