Control statement
Automatically terminate a user session after [Organization-defined: conditions or trigger events].
Discussion
Session termination addresses the termination of user-initiated logical sessions (in contrast to [SC-10](#sc-10) , which addresses the termination of network connections associated with communications sessions (i.e., network disconnect)). A logical session (for local, network, and remote access) is initiated whenever a user (or process acting on behalf of a user) accesses an organizational system. Such user sessions can be terminated without terminating network sessions. Session termination ends all processes associated with a user’s logical session except for those processes that are specifically created by the user (i.e., session owner) to continue after the session is terminated. Conditions or trigger events that require automatic termination of the session include organization-defined periods of user inactivity, targeted responses to certain types of incidents, or time-of-day restrictions on system use.
Organization-defined parameters
These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.
From control text to operational evidence
Use Session Termination as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to identity, authorization, least privilege, session boundaries, and access lifecycle governance.
Implementation workflow
- Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
- Resolve each organization-defined parameter before declaring the control implemented.
- Document how the implementation satisfies every clause of the official control statement.
- Collect evidence as a normal byproduct of operation rather than only before an assessment.
- Review exceptions, changes, and monitoring results on a risk-based cadence.
Evidence examples
- access approvals and entitlement records
- role and group configuration exports
- periodic access review results
- authentication and authorization logs
Common failure patterns
- standing privileges that outlive business need
- shared or orphaned accounts
- access rules implemented differently across systems
- approvals that cannot be traced to actual permissions
Questions practitioners should ask
- What risk decision is this control intended to support in this system?
- Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
- Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
- What event or threshold requires the implementation to be reviewed or changed?
Assessment objectives and methods
Show the assessment objective
a user session is automatically terminated after [Organization-defined: conditions or trigger events].
Examine
- Access control policy
- procedures addressing session termination
- system design documentation
- system configuration settings and associated documentation
- list of conditions or trigger events requiring session disconnect
- system audit records
- system security plan
- other relevant documents or records
Interview
- System/network administrators
- organizational personnel with information security responsibilities
- system developers
Test
- Automated mechanisms implementing user session termination
Related controls
These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.
Control enhancements
Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.
AC-12(1) — User-initiated Logouts
Provide a logout capability for user-initiated communications sessions whenever authentication is used to gain access to [Organization-defined: information resources].
Official discussion
Information resources to which users gain access via authentication include local workstations, databases, and password-protected websites or web-based services.
Organization-defined parameters (1)
Assessment objectives and methods
a logout capability is provided for user-initiated communications sessions whenever authentication is used to gain access to [Organization-defined: information resources].
Examine
- Access control policy
- procedures addressing session termination
- user logout messages
- system design documentation
- system configuration settings and associated documentation
- system audit records
- system security plan
- other relevant documents or records
Interview
- System/network administrators
- organizational personnel with information security responsibilities
- system developers
Test
- System session termination mechanisms
- logout capabilities for user-initiated communications sessions
AC-12(2) — Termination Message
Display an explicit logout message to users indicating the termination of authenticated communications sessions.
Official discussion
Logout messages for web access can be displayed after authenticated sessions have been terminated. However, for certain types of sessions, including file transfer protocol (FTP) sessions, systems typically send logout messages as final messages prior to terminating sessions.
Assessment objectives and methods
an explicit logout message is displayed to users indicating the termination of authenticated communication sessions.
Examine
- Access control policy
- procedures addressing session termination
- user logout messages
- system design documentation
- system configuration settings and associated documentation
- system audit records
- system security plan
- other relevant documents or records
Interview
- System/network administrators
- organizational personnel with information security responsibilities
- system developers
Test
- System session termination mechanisms
- display of logout messages
AC-12(3) — Timeout Warning Message
Display an explicit message to users indicating that the session will end in [Organization-defined: time].
Official discussion
To increase usability, notify users of pending session termination and prompt users to continue the session. The pending session termination time period is based on the parameters defined in the [AC-12](#ac-12) base control.
Organization-defined parameters (1)
Assessment objectives and methods
an explicit message to users is displayed indicating that the session will end in [Organization-defined: time].
Examine
- Access control policy
- procedures addressing session termination
- time until end of session messages
- system design documentation
- system configuration settings and associated documentation
- system audit records
- system security plan
- other relevant documents or records
Interview
- System/network administrators
- organizational personnel with information security responsibilities
- system developers
Test
- System session termination mechanisms
- display of end of session time
Authoritative sources
Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST. Official control requirements and interpretations remain with NIST and the responsible authorizing organization.