Skip to content

Commit

Permalink
Updated 1.3.2 to resolve OWASP#2101
Browse files Browse the repository at this point in the history
  • Loading branch information
ryarmst authored Oct 21, 2024
1 parent 932d455 commit 7a9b54e
Showing 1 changed file with 1 addition and 0 deletions.
1 change: 1 addition & 0 deletions 5.0/en/0x10-V1-Architecture.md
Original file line number Diff line number Diff line change
Expand Up @@ -50,6 +50,7 @@ There is no single pattern that suits all applications. Therefore, it is infeasi
| # | Description | L1 | L2 | L3 | CWE |
| :---: | :--- | :---: | :---: | :---: | :---: |
| **1.3.1** | [ADDED] Verify that the user's session inactivity period and maximum session lifetime before reauthentication are documented, appropriate in combination with other controls, and that documentation includes justification for any deviations from NIST SP 800-63B reauthentication requirements. |||| |
| **1.3.2** | [ADDED] Verify that the documentation defines how many concurrent (parallel) sessions are allowed for one account as well as the intended behaviours and actions to be taken when the maximum number of active sessions is reached. |||| |

## V1.4 Access Control Documentation

Expand Down

0 comments on commit 7a9b54e

Please sign in to comment.