The system should enforce automatic session termination or require user re-authentication after a defined period of user inactivity
The maximum allowable period of inactivity before session timeout should be determined by risk assessment of the client company but must not exceed xx minutes. Session management processes should be ready for future adjustment as security needs evolve. The solution shall also support regular monitoring and review of timeout settings to ensure compliance and the continued protection of sensitive data.
Siirretty Canny-portaalista. Alkuperäinen ehdotus 12.9.2025, 1 ääntä: nocfo.canny.io
Log in to comment and vote
No comments yet
Be the first to share your thoughts.