SC-23(1): Invalidate Session Identifiers At Logout

CSF v1.1 References:

Threats Addressed:


(Not part of any baseline)

Next Version:

Control Statement

The information system invalidates session identifiers upon user logout or other session termination.

Supplemental Guidance

This control enhancement curtails the ability of adversaries from capturing and continuing to employ previously valid session IDs.