{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"technical","domain":"Access Control & Identity Management","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-ACCESS-12","description":"Sessions lock with a pattern-hiding display after a defined period of inactivity and require re-authentication to resume. Sessions terminate automatically on defined conditions such as extended inactivity, and concurrent sessions are limited per account. Re-authentication is required for sensitive operations, privilege changes, or after defined intervals.","details":{"control_category":"technical","control_type":"preventive","domain":"Access Control & Identity Management","guidance":[],"members":[{"control_id":"AC-10","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"AC-11","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"AC-12","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"IA-11","coverage":"full","framework":"nist-800-53","relationship":"superset_of"}],"statement":"Sessions lock with a pattern-hiding display after a defined period of inactivity and require re-authentication to resume. Sessions terminate automatically on defined conditions such as extended inactivity, and concurrent sessions are limited per account. Re-authentication is required for sensitive operations, privilege changes, or after defined intervals.","title":"Lock, limit, and terminate user sessions","unified_id":"UC-ACCESS-12"},"id":"uc:UC-ACCESS-12","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-ACCESS-12","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"UC-ACCESS-12 — Lock, limit, and terminate user sessions","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1c3eb929924f65eb0da5779c3c4a25573b839f3df4c378f9352812dac8c94e4a","properties":{},"sourceDetailPath":"/data/v1/records/wf-c5-907af9a4.json","sourceId":"wf:C5","targetDetailPath":"/data/v1/records/uc-uc-access-12-8ef9e477.json","targetId":"uc:UC-ACCESS-12","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2358a2c148d8bccf7f1119a0dc058883c08985287682e8634af5edb8d53fbcfa","properties":{"control_id":"AC-10","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-access-12-8ef9e477.json","sourceId":"uc:UC-ACCESS-12","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ac-10-97228291.json","targetId":"ctrl:nist-800-53:AC-10","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:44320f492b85154a5f967bc6fdb91b61bf8ec308c528c8165bb74917547b0316","properties":{},"sourceDetailPath":"/data/v1/records/wf-c9-75fb1752.json","sourceId":"wf:C9","targetDetailPath":"/data/v1/records/uc-uc-access-12-8ef9e477.json","targetId":"uc:UC-ACCESS-12","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6662d9807d217d144f6385ea403d7146cec254119ac9b1129452ea610713104e","properties":{"control_id":"AC-12","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-access-12-8ef9e477.json","sourceId":"uc:UC-ACCESS-12","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ac-12-6fb08a51.json","targetId":"ctrl:nist-800-53:AC-12","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:685b36d14de767557dc4718fdf300957718a727962b517b25617079a3d37bf14","properties":{},"sourceDetailPath":"/data/v1/records/wf-c31-c58b2f38.json","sourceId":"wf:C31","targetDetailPath":"/data/v1/records/uc-uc-access-12-8ef9e477.json","targetId":"uc:UC-ACCESS-12","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:87a4372501910e18e05b608c3a88f895fe36673eb8558e2b013400365214b906","properties":{"rationale":"Session lock on unattended workstations reduces the impact of unauthorized physical access to equipment, e.g. after tailgating.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-12-8ef9e477.json","sourceId":"uc:UC-ACCESS-12","targetDetailPath":"/data/v1/records/risk-phys-inadequate-facility-access-a83f3330.json","targetId":"risk:phys-inadequate-facility-access","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8c91587da707a581160cfdb73b3a43b26c6a24585b36d99068acdf028a759122","properties":{"rationale":"Pattern-hiding lock of unattended sessions prevents unauthorized use of an authenticated workstation.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-12-8ef9e477.json","sourceId":"uc:UC-ACCESS-12","targetDetailPath":"/data/v1/records/risk-access-unauthorized-use-equipment-d2082944.json","targetId":"risk:access-unauthorized-use-equipment","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:97979f542865a8450a21cfbc3a41b77acd617ad5ea8619189e3fad0c9d09ffd4","properties":{"rationale":"Inactivity termination, concurrent-session limits, and re-authentication for sensitive operations directly shrink the window and impact of hijacked sessions.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-12-8ef9e477.json","sourceId":"uc:UC-ACCESS-12","targetDetailPath":"/data/v1/records/risk-net-session-hijacking-434ddd0c.json","targetId":"risk:net-session-hijacking","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:98a7a520f773385d9efa5a0207ce5da39ae438b63d4e2f8bb7d2d9b48845cca7","properties":{"control_id":"IA-11","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-access-12-8ef9e477.json","sourceId":"uc:UC-ACCESS-12","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ia-11-0b2e10ff.json","targetId":"ctrl:nist-800-53:IA-11","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c3bc6914e6776492f91e9ce90dd29c2a9c9c1f0960583810fb7c725d55c0d967","properties":{"rationale":"Inactivity session lock requiring re-authentication directly fixes the missing lock/logout on unattended workstations.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-12-8ef9e477.json","sourceId":"uc:UC-ACCESS-12","targetDetailPath":"/data/v1/records/risk-access-weak-authentication-4e35bdb2.json","targetId":"risk:access-weak-authentication","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f6d15f7726201471fe828f96997e0d58d1be22ccd3a061dc0253ac694297bc29","properties":{"control_id":"AC-11","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-access-12-8ef9e477.json","sourceId":"uc:UC-ACCESS-12","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ac-11-9666db4b.json","targetId":"ctrl:nist-800-53:AC-11","type":"maps_to"}],"schemaVersion":1}
