Check: SRG-APP-000297-CTR-000705
Container Platform SRG:
SRG-APP-000297-CTR-000705
(in versions v1 r5 through v1 r1)
Title
Access to the container platform must display an explicit logout message to user indicating the reliable termination of authenticated communication sessions. (Cat III impact)
Discussion
Access to the container platform will occur through web and terminal sessions. Any web interfaces must conform to application and web security requirements. Terminal access to the container platform and its components must provide a logout facility that terminates the connection to the component or the platform.
Check Content
Review documentation and configuration settings to determine if the container platform displays a logout message. If the container platform does not display a logout message, this is a finding.
Fix Text
Configure the container platform components to display an explicit logout message to users.
Additional Identifiers
Rule ID: SV-233149r879675_rule
Vulnerability ID: V-233149
Group Title: SRG-APP-000297
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-002364 |
The information system displays an explicit logout message to users indicating the reliable termination of authenticated communications sessions. |
Controls
Number | Title |
---|---|
AC-12 (1) |
User-Initiated Logouts / Message Displays |