STIGQter STIGQter: STIG Summary: Web Server Security Requirements Guide Version: 4 Release: 5 Benchmark Date: 01 Jul 2026:

The web server must set an inactive timeout for sessions.

DISA Rule

SV-206415r1043182_rule

Vulnerability Number

V-206415

Group Title

SRG-APP-000295

Rule Version

SRG-APP-000295-WSR-000134

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the web server to close inactive sessions after 5 minutes for high-risk applications, 10 minutes for medium-risk applications, or 20 minutes for low-risk applications.

Check Contents

Review the hosted applications, web server documentation and deployed configuration to verify that the web server will close an open session after a configurable time of inactivity.

If the web server does not close sessions after a configurable time of inactivity or the amount of time is configured higher than 5 minutes for high-risk applications, 10 minutes for medium-risk applications, or 20 minutes for low-risk applications, this is a finding.

Vulnerability Number

V-206415

Documentable

False

Rule Version

SRG-APP-000295-WSR-000134

Severity Override Guidance

Review the hosted applications, web server documentation and deployed configuration to verify that the web server will close an open session after a configurable time of inactivity.

If the web server does not close sessions after a configurable time of inactivity or the amount of time is configured higher than 5 minutes for high-risk applications, 10 minutes for medium-risk applications, or 20 minutes for low-risk applications, this is a finding.

Check Content Reference

M

Target Key

2910