unified
UC-ACCESS-12 — Lock, limit, and terminate user sessions
Sessions lock with a pattern-hiding display after a defined period of inactivity and require re-authentication to resume. Sessions terminate automatically on defined conditions such as extended inactivity, and concurrent sessions are limited per account. Re-authentication is required for sensitive operations, privilege changes, or after defined intervals.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Access Control & Identity Management
- type
- preventive
- category
- technical
Details
- unified_id
- UC-ACCESS-12
- title
- Lock, limit, and terminate user sessions
- statement
- Sessions lock with a pattern-hiding display after a defined period of inactivity and require re-authentication to resume. Sessions terminate automatically on defined conditions such as extended inactivity, and concurrent sessions are limited per account. Re-authentication is required for sensitive operations, privilege changes, or after defined intervals.
- domain
- Access Control & Identity Management
- control_type
- preventive
- control_category
- technical
- members
- framework
- nist-800-53
- control_id
- AC-10
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- AC-11
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- AC-12
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- IA-11
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- Identity Assurance Review oversees UC-ACCESS-12 — Lock, limit, and terminate user sessions
- UC-ACCESS-12 — Lock, limit, and terminate user sessions maps_to AC-10 — Concurrent Session Control
- framework
- nist-800-53
- control_id
- AC-10
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Security Control Assessment & POA&M Remediation tests UC-ACCESS-12 — Lock, limit, and terminate user sessions
- UC-ACCESS-12 — Lock, limit, and terminate user sessions maps_to AC-12 — Session Termination
- framework
- nist-800-53
- control_id
- AC-12
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Authentication Platform & Session Policy Operations operates UC-ACCESS-12 — Lock, limit, and terminate user sessions
- UC-ACCESS-12 — Lock, limit, and terminate user sessions mitigates Inadequate physical protection and access controls
- strength
- related
- rationale
- Session lock on unattended workstations reduces the impact of unauthorized physical access to equipment, e.g. after tailgating.
- UC-ACCESS-12 — Lock, limit, and terminate user sessions mitigates Unauthorized use of equipment and unauthorized access escalation
- strength
- related
- rationale
- Pattern-hiding lock of unattended sessions prevents unauthorized use of an authenticated workstation.
- UC-ACCESS-12 — Lock, limit, and terminate user sessions mitigates Session hijacking and unauthorized-protocol egress
- strength
- primary
- rationale
- Inactivity termination, concurrent-session limits, and re-authentication for sensitive operations directly shrink the window and impact of hijacked sessions.
- UC-ACCESS-12 — Lock, limit, and terminate user sessions maps_to IA-11 — Re-authentication
- framework
- nist-800-53
- control_id
- IA-11
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-ACCESS-12 — Lock, limit, and terminate user sessions mitigates Weak authentication and password management
- strength
- primary
- rationale
- Inactivity session lock requiring re-authentication directly fixes the missing lock/logout on unattended workstations.
- UC-ACCESS-12 — Lock, limit, and terminate user sessions maps_to AC-11 — Device Lock
- framework
- nist-800-53
- control_id
- AC-11
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.