Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

NIST SP 800-53 Learning Center

AC-12 — Session Termination

Read the official control and assessment content, then use the separately labeled Bare Metal Cyber perspective to connect the requirement to implementation, evidence, and sustained operation.

3Enhancements
1Parameters
2Baseline memberships
3Assessment methods

AC — Access Control · NIST SP 800-53 Release 5.2.0

ModerateHigh
Official NIST control content

Control statement

Automatically terminate a user session after [Organization-defined: conditions or trigger events].

Official NIST discussion

Discussion

Session termination addresses the termination of user-initiated logical sessions (in contrast to [SC-10](#sc-10) , which addresses the termination of network connections associated with communications sessions (i.e., network disconnect)). A logical session (for local, network, and remote access) is initiated whenever a user (or process acting on behalf of a user) accesses an organizational system. Such user sessions can be terminated without terminating network sessions. Session termination ends all processes associated with a user’s logical session except for those processes that are specifically created by the user (i.e., session owner) to continue after the session is terminated. Conditions or trigger events that require automatic termination of the session include organization-defined periods of user inactivity, targeted responses to certain types of incidents, or time-of-day restrictions on system use.

Official OSCAL parameters

Organization-defined parameters

These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.

conditions or trigger eventsconditions or trigger events requiring session disconnect are defined;
Original Bare Metal Cyber perspective

From control text to operational evidence

Use Session Termination as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to identity, authorization, least privilege, session boundaries, and access lifecycle governance.

Implementation workflow

  • Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
  • Resolve each organization-defined parameter before declaring the control implemented.
  • Document how the implementation satisfies every clause of the official control statement.
  • Collect evidence as a normal byproduct of operation rather than only before an assessment.
  • Review exceptions, changes, and monitoring results on a risk-based cadence.

Evidence examples

  • access approvals and entitlement records
  • role and group configuration exports
  • periodic access review results
  • authentication and authorization logs

Common failure patterns

  • standing privileges that outlive business need
  • shared or orphaned accounts
  • access rules implemented differently across systems
  • approvals that cannot be traced to actual permissions

Questions practitioners should ask

  • What risk decision is this control intended to support in this system?
  • Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
  • Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
  • What event or threshold requires the implementation to be reviewed or changed?
Official NIST SP 800-53A content

Assessment objectives and methods

Show the assessment objective

a user session is automatically terminated after [Organization-defined: conditions or trigger events].

Examine

  • Access control policy
  • procedures addressing session termination
  • system design documentation
  • system configuration settings and associated documentation
  • list of conditions or trigger events requiring session disconnect
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • system developers

Test

  • Automated mechanisms implementing user session termination
Official relationships

Related controls

These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.

Official NIST enhancements

Control enhancements

Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.

Official NIST control enhancement

AC-12(1) — User-initiated Logouts

Provide a logout capability for user-initiated communications sessions whenever authentication is used to gain access to [Organization-defined: information resources].

Official discussion

Information resources to which users gain access via authentication include local workstations, databases, and password-protected websites or web-based services.

Organization-defined parameters (1)
information resourcesinformation resources for which a logout capability for user-initiated communications sessions is required are defined;
Assessment objectives and methods

a logout capability is provided for user-initiated communications sessions whenever authentication is used to gain access to [Organization-defined: information resources].

Examine

  • Access control policy
  • procedures addressing session termination
  • user logout messages
  • system design documentation
  • system configuration settings and associated documentation
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • system developers

Test

  • System session termination mechanisms
  • logout capabilities for user-initiated communications sessions
Official NIST control enhancement

AC-12(2) — Termination Message

Display an explicit logout message to users indicating the termination of authenticated communications sessions.

Official discussion

Logout messages for web access can be displayed after authenticated sessions have been terminated. However, for certain types of sessions, including file transfer protocol (FTP) sessions, systems typically send logout messages as final messages prior to terminating sessions.

Assessment objectives and methods

an explicit logout message is displayed to users indicating the termination of authenticated communication sessions.

Examine

  • Access control policy
  • procedures addressing session termination
  • user logout messages
  • system design documentation
  • system configuration settings and associated documentation
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • system developers

Test

  • System session termination mechanisms
  • display of logout messages
Official NIST control enhancement

AC-12(3) — Timeout Warning Message

Display an explicit message to users indicating that the session will end in [Organization-defined: time].

Official discussion

To increase usability, notify users of pending session termination and prompt users to continue the session. The pending session termination time period is based on the parameters defined in the [AC-12](#ac-12) base control.

Organization-defined parameters (1)
timetime until the end of session for display to users is defined;
Assessment objectives and methods

an explicit message to users is displayed indicating that the session will end in [Organization-defined: time].

Examine

  • Access control policy
  • procedures addressing session termination
  • time until end of session messages
  • system design documentation
  • system configuration settings and associated documentation
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • system developers

Test

  • System session termination mechanisms
  • display of end of session time
Source record

Authoritative sources