Session Management
What is Session Management?
The process of handling user sessions securely, including session creation, token generation, timeout enforcement, and proper session termination.
Terms that appear alongside session management
Each of these is named in at least one of the same controls as session management. The number is how many controls name both.
- authentication 11 shared controls
- access control 6 shared controls
- nist 6 shared controls
- least privilege 5 shared controls
- separation of duties 4 shared controls
- authorization 4 shared controls
- owasp 3 shared controls
- multi factor authentication 3 shared controls
Frameworks that govern session management
What the standards actually require on session management
Requirements naming session management across 6 standards, quoted from the control text.
UR E27 requires equipment-level user authentication and authorization mechanisms aligned with IEC 62443-4-2 FR 1 (Identification and Authentication Control) and FR 2 (Use Control).
IACS-UR-E27-Equipment-UserAuth-Authentication-Authorization · IACS UR E27 - Equipment User Authentication + Authorization + Session Management + Privileged Access →Per OWASP ASVS V3: implement secure session management. Requirements include (a) generate cryptographically random session tokens of sufficient entropy + (b) protect tokens against session fixation + replay + theft + (c) implement secure cookie attributes (Sec...
OWASPASVS-3 · Session Management (V3) →Session management controls. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: System & Communications Protection.
BSI-11 · Session management controls →Session management controls. Implements CyFun PR.AC-7 / PR.PT-4: sessions are authenticated and managed to protect confidentiality and integrity.
BE-CF-11 · Session management controls →Protect interactions with the service using session management that meets at least the current state of the art and withstands known attacks, and invalidate a session once detected as inactive using a timeout configurable by the provider or, where technically...
C5-PSS-06 · Session Management →GLI-33 geolocation + mobile + internet wagering security. GEOLOCATION VERIFICATION: in regulated jurisdictions (US states + provinces) wager acceptance must be CONTINUOUSLY GEO-VERIFIED to ensure player is physically within authorized boundary;
GLI33-Geolocation-Mobile-Internet-Wagering · GLI-33 Geolocation Verification, Mobile and Internet Wagering Security, Session Management →Questions people ask about session management
What is Session Management?
Why is Session Management important for compliance?
Which compliance frameworks address Session Management?
Where can I learn more about Session Management?
See how Session Management applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.