Authentication - Enforcement of Periodic Subscriber Reauthentication, v1.0

Subscribers must reauthenticate after periods of inactivity according to the AAL being operated at.

Assessment Step

1
Inactivity Timeouts (InactivityTimeouts)
Does inactivity force reauthentication? Specify the inactivity timeout, for AAL2 the maximum is 1800 and for AAL3 the maximum is 900.
Artifact
A1
Provide evidence (e.g. policies, operational details) that inactivity will force reauthentication at AAL2 and AAL3.
Parameters
All factors required to reauthenticaterequired
BOOLEAN : All factors required to reauthenticate
Max Inactivity Timerequired
NUMBER : The maximum time in seconds of inactivity before reauthentication is required

Conformance Criteria (1)

C1
  • Reauthentication of the subscriber SHALL be repeated following any period of inactivity lasting 30 minutes or longer.
  • Reauthentication of the subscriber SHALL be repeated following any period of inactivity lasting 15 minutes or longer. Reauthentication SHALL use both authentication factors.
Citation
NIST SP 800-63B
Sections 4.2.3 and 4.3.3