Description
The current default session timeout is 60 minutes, but STIG requires:
- 10 minutes for administrative users
- 15 minutes for non-privileged users
Current Implementation
- Default timeout: 60 minutes (config/vulcan.default.yml:29)
- Configured via:
VULCAN_SESSION_TIMEOUT environment variable
Proposed Changes
- Change default timeout in
config/vulcan.default.yml from 60 to 10 minutes
- Add comments about STIG compliance requirements
- Update documentation to reflect the change
Files to Update
config/vulcan.default.yml line 29
- Documentation files referencing session timeout
Acceptance Criteria
References
- NIST SP 800-53 AC-12
- Application Security & Development STIG V-222389, V-222390
Description
The current default session timeout is 60 minutes, but STIG requires:
Current Implementation
VULCAN_SESSION_TIMEOUTenvironment variableProposed Changes
config/vulcan.default.ymlfrom 60 to 10 minutesFiles to Update
config/vulcan.default.ymlline 29Acceptance Criteria
References