AC-12(2): Termination Message

Control Family:

Access Control

CSF v1.1 References:


(Not part of any baseline)

Control is new to this version of the control set.

Control Statement

Display an explicit logout message to users indicating the termination of authenticated communications sessions.

Supplemental Guidance

Logout messages for web access can be displayed after authenticated sessions have been terminated. However, for certain types of sessions, including file transfer protocol (FTP) sessions, systems typically send logout messages as final messages prior to terminating sessions.