Skip to content

Session Management

What is Session Management?

The process of handling user sessions securely, including session creation, token generation, timeout enforcement, and proper session termination.

Information Security

Each of these is named in at least one of the same controls as session management. The number is how many controls name both.

What the standards actually require on session management

Requirements naming session management across 6 standards, quoted from the control text.

UR E27 requires equipment-level user authentication and authorization mechanisms aligned with IEC 62443-4-2 FR 1 (Identification and Authentication Control) and FR 2 (Use Control).

IACS-UR-E27-Equipment-UserAuth-Authentication-Authorization · IACS UR E27 - Equipment User Authentication + Authorization + Session Management + Privileged Access
OWASP ASVS2 controls

Per OWASP ASVS V3: implement secure session management. Requirements include (a) generate cryptographically random session tokens of sufficient entropy + (b) protect tokens against session fixation + replay + theft + (c) implement secure cookie attributes (Sec...

OWASPASVS-3 · Session Management (V3)

Session management controls. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: System & Communications Protection.

BSI-11 · Session management controls

Session management controls. Implements CyFun PR.AC-7 / PR.PT-4: sessions are authenticated and managed to protect confidentiality and integrity.

BE-CF-11 · Session management controls
C5 (Germany)1 control

Protect interactions with the service using session management that meets at least the current state of the art and withstands known attacks, and invalidate a session once detected as inactive using a timeout configurable by the provider or, where technically...

C5-PSS-06 · Session Management

GLI-33 geolocation + mobile + internet wagering security. GEOLOCATION VERIFICATION: in regulated jurisdictions (US states + provinces) wager acceptance must be CONTINUOUSLY GEO-VERIFIED to ensure player is physically within authorized boundary;

GLI33-Geolocation-Mobile-Internet-Wagering · GLI-33 Geolocation Verification, Mobile and Internet Wagering Security, Session Management

Questions people ask about session management

What is Session Management?
The process of handling user sessions securely, including session creation, token generation, timeout enforcement, and proper session termination.
Why is Session Management important for compliance?
Session Management is a key concept in Information Security. Understanding session management helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Session Management?
Session Management appears in the requirement text of IACS Unified Requirements E26/E27 - Cyber Resilience of Ships and On-Board Systems, OWASP ASVS, BSI IT-Grundschutz, Belgium CyberFundamentals, C5 (Germany). Across these standards we have identified 8 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Session Management?
Explore our compliance framework pages to see how session management applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Session Management applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.