SC-23(1): Invalidate Session Identifiers at Logout
Control Family:
Parent Control:
CSF v1.1 References:
Threats Addressed:
Baselines:
(Not part of any baseline)
Previous Version:
- NIST Special Publication 800-53 Revision 4:
- SC-23(1): Invalidate Session Identifiers At Logout
Control Statement
Invalidate session identifiers upon user logout or other session termination.
Supplemental Guidance
Invalidating session identifiers at logout curtails the ability of adversaries to capture and continue to employ previously valid session IDs.