{"data":{"id":"AC-12","name":"Session Termination","family":"AC","family_name":"Access Control","withdrawn":false,"description":"Automatically terminate a user session after [Assignment: organization-defined conditions or trigger events requiring session disconnect].","supplemental_guidance":"Session termination addresses the termination of user-initiated logical sessions (in contrast to SC-10, which addresses the termination of network connections associated with communications sessions (i.e., network disconnect)). A logical session (for local, network, and remote access) is initiated whenever a user (or process acting on behalf of a user) accesses an organizational system. Such user sessions can be terminated without terminating network sessions. Session termination ends all processes associated with a user’s logical session except for those processes that are specifically created by the user (i.e., session owner) to continue after the session is terminated. Conditions or trigger events that require automatic termination of the session include organization-defined periods of user inactivity, targeted responses to certain types of incidents, or time-of-day restrictions on system use.","enhancements":[{"id":"AC-12(01)","name":"User-initiated Logouts","statement":"Provide a logout capability for user-initiated communications sessions whenever authentication is used to gain access to [Assignment: organization-defined information resources].","baselines":[]},{"id":"AC-12(02)","name":"Termination Message","statement":"Display an explicit logout message to users indicating the termination of authenticated communications sessions.","baselines":[]},{"id":"AC-12(03)","name":"Timeout Warning Message","statement":"Display an explicit message to users indicating that the session will end in [Assignment: organization-defined time until end of session].","baselines":[]}],"baseline_low":false,"baseline_moderate":true,"baseline_high":true,"nist_800_53":{"rev5":{"id":"AC-12","name":"Session Termination","description":"Automatically terminate a user session after [Assignment: organization-defined conditions or trigger events requiring session disconnect].","discussion":"Session termination addresses the termination of user-initiated logical sessions (in contrast to SC-10, which addresses the termination of network connections associated with communications sessions (i.e., network disconnect)). A logical session (for local, network, and remote access) is initiated whenever a user (or process acting on behalf of a user) accesses an organizational system. Such user sessions can be terminated without terminating network sessions. Session termination ends all processes associated with a user’s logical session except for those processes that are specifically created by the user (i.e., session owner) to continue after the session is terminated. Conditions or trigger events that require automatic termination of the session include organization-defined periods of user inactivity, targeted responses to certain types of incidents, or time-of-day restrictions on system use.","related_controls":["MA-04","SC-10","SC-23"],"baseline_low":false,"baseline_moderate":true,"baseline_high":true,"baseline_privacy":false,"new_in_rev5":false,"changes_from_rev4":""}},"compliance_mappings":{"iso_27001_2022":[],"iso_27002_2022":["5.15"],"cobit_2019":["DSS05"],"pci_dss_v4":[],"nist_csf_2":["PR.AA-03"],"cis_controls_v8":[],"soc2_tsc":[],"finos_ccc":[],"iso_42001_2023":[],"iec_62443":[],"asd_e8":[],"nis2":["Art. 21(2)(i)"],"apra_cps_234":[],"mas_trm":["9"],"pra_op_resilience":[],"bsi_grundschutz":["ORP.4"],"anssi":["Hygiene.12","SecNumCloud.10.6"],"osfi_b13":["B-13.3.2"],"finma_circular":["IV.B.d(59)","IV.C(61)"],"gdpr":["Art.32(1)(b)"],"dora":["Art.9(4)(c)"],"bio2":["5.15"],"rbi_csf":["Annex1.8"],"fisc":["FISC.T2"],"lgpd_bcb":[],"hkma_tme1":["TME1.8.4"],"mlps_2":["8.1.3.2","8.1.4.10"],"dnb_good_practice":[],"cra":[],"swift_cscf":["SWIFT.2.6"],"cbb_tm":["TM-6"],"cbuae":["CR-4"],"nca_ecc":["2-2"],"qatar_nia":["AC"],"sama_csf":["3.1"],"uae_ia":["T9"],"bog_cisd":["CISD-VIII"],"bom_ctrm":["3.3"],"cbe_csf":["CTO-1"],"cbn_csf":["Part3.2"],"sa_js2":["JS2-7.1"],"bot_cyber":["Ch2.2"],"eba_ict":["3.4.2"],"ecb_croe":["CROE.2.3.1"],"hipaa_sr":["§164.312(a)(2)(iii)"],"iosco_cyber":["PROT-1"],"sebi_cscrf":["PR.AA"],"cmmc_2":["AC"],"nerc_cip":[],"nrc_73_54":[],"tsa_psd":[],"ieee_1686":["5.8"],"ferc_cip":[],"doe_c2m2":[],"api_1164":[],"awia":[],"iaea_nss":[],"pci_pts":[],"fips_140":[],"cbest":[],"tiber_eu":[],"pci_hsm":[],"common_criteria":["CC Part 2 — FRU/FTA/FTP"],"isae_3402":[],"fca_sysc_13":[],"fda_21_cfr_11":["§11.10(d)","§11.200(a)(1)(i)"],"fda_cyber":[],"hitrust_csf":["01.c"],"iso_27799":["9.4"],"lloyds_ms":["MS8.3"],"naic_ds":[],"nhs_dspt":[],"pra_ss1_23":[],"solvency_ii":["EIOPA-ICT-4.4"],"owasp_masvs_v2":[],"csa_ccm_v4":[],"csa_aicm":[],"ccss_v9":[],"mica":[],"basel_sco60":[],"bssc":[],"sec_custody_digital":[],"dpdpa":[]},"attack_techniques":[{"id":"T1072","name":"Software Deployment Tools","tactics":["execution","lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Automatic session termination for software deployment tool consoles after inactivity limits adversary abuse of unattended management sessions by ensuring idle deployment tool connections are closed before they can be exploited."},{"id":"T1185","name":"Browser Session Hijacking","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Session termination after defined inactivity periods limits browser session hijacking by reducing the window during which authenticated browser sessions remain valid for adversary interception and exploitation."},{"id":"T1563","name":"Remote Service Session Hijacking","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Automatic termination of idle remote service sessions—including RDP, SSH, and VNC—limits adversary session hijacking by ensuring dormant sessions are not available for takeover during lateral movement."},{"id":"T1021.001","name":"Remote Desktop Protocol","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Automatic RDP session termination after inactivity prevents adversaries from hijacking disconnected but active Remote Desktop sessions by ensuring idle sessions are fully terminated rather than left in a disconnected state."},{"id":"T1505.005","name":"Terminal Services DLL","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Session termination policies for Terminal Services that close idle sessions prevent adversary exploitation of persistent RDP sessions, limiting the effectiveness of Terminal Services DLL-based persistence mechanisms."},{"id":"T1563.002","name":"RDP Hijacking","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Automatic termination of disconnected RDP sessions directly counters RDP hijacking by ensuring that disconnected sessions are fully closed rather than remaining available for adversary takeover via tscon or session shadowing."}],"metadata":{"last_reviewed":"2026-10-03","review_notes":"2026-10-03: nist_csf_2 PR.AA-03 added from NIST's CSF 2.0 to SP 800-53 Rev 5.2.0 crosswalk (OLIR entry 186), which OSA's mapping now takes as its base. 2026-10-03: baselines LMH to -MH, from NIST SP 800-53B Release 5.2.0.","mapping_status":"complete"},"function":"preventative","used_by_patterns":["SP-001","SP-002","SP-008","SP-016","SP-019","SP-029","SP-030","SP-032","SP-033","SP-037"]}}