Check: 4.028
Win2k8 Audit:
4.028
(in version v6 r1.22)
Title
Amount of idle time required before suspending a session is improperly set. (Cat III impact)
Discussion
Administrators should use this setting to control when a computer disconnects an inactive SMB session. If client activity resumes, the session is automatically reestablished. This protects critical and sensitive network data from exposure to unauthorized personnel with physical access to the computer.
Check Content
Fix Text
Configure the policy value for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> “Microsoft Network Server: Amount of idle time required before suspending a session” to ”15” minutes or less.
Additional Identifiers
Rule ID: SV-29226r1_rule
Vulnerability ID: V-1174
Group Title: Idle Time Before Suspending a Session.
Expert Comments
Expert comments are only available to logged-in users.
CCIs
CCIs tied to check.
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Controls tied to check. These are derived from the CCIs shown above.
Number | Title |
---|---|
No controls are assigned to this check |