Rule ID
SV-288143r1252014_rule
Version
V1R0.1
CCIs
If cached authentication information is out of date, the validity of the authentication information may be questionable. NIST SP 800-63B defines the value for the termination of cached authenticators.
Review application server documentation and deployed configuration to ensure the application prohibits the use of cached authenticators after an organization-defined time period. If the application does not prohibit the use of cached authenticators after an organization-defined time period, this is a finding.
Configure the application to prohibit the use of cached authenticators after an organization-defined time period.