AC-2(5): Inactivity Logout

Control Family:

Access Control

CSF v1.1 References:

Threats Addressed:

Baselines:

  • Moderate
  • High
  • OT Moderate (SP 800-82r3)
  • OT High (SP 800-82r3)

Previous Version:

Control Statement

Require that users log out when [Assignment: organization-defined time period of expected inactivity or description of when to log out].

Supplemental Guidance

Inactivity logout is behavior- or policy-based and requires users to take physical action to log out when they are expecting inactivity longer than the defined period. Automatic enforcement of inactivity logout is addressed by AC-11.

OT Discussion

This control enhancement defines situations or timeframes in which users log out of accounts in the policy. Automatic enforcement is not addressed by this control enhancement. Organizations determine whether this control enhancement is appropriate for the mission and/or functions of the OT system and define the timeframe or scenarios. If no timeframe or scenarios apply, the organization-defined parameter reflects as much.