STIGUI
V-283936CAT II — Medium severitySV-283936r1206162_rule

Fly Server must terminate sessions after 10 minutes.

Rule version FLYS-00-000100 · STIG v1 · 2026-06-15

Discussion

Terminating an idle session within a short time period reduces the window of opportunity for unauthorized personnel to take control of a management session enabled on the console or console port that has been left unattended. In addition, quickly terminating an idle session will also free up resources committed by the managed network element.

Terminating network connections associated with communications sessions includes, for example, de-allocating associated TCP/IP address/port pairs at the operating system level, or de-allocating networking assignments at the application level if multiple application sessions are using a single, operating system-level network connection. This does not mean that the application terminates all sessions or network access; it only ends the inactive session and releases the resources associated with that session.

Check

Check the Fly Server Manager session setting: - Log on to Fly Server Manager with an admin account. - On the Management >> General Settings page, click the "System Option" tab. - Verify the "Session Will Expire After Inactivity for:" setting is selected.

If this setting is not 10 minutes, this is a finding.

Fix

Configure the Fly Server Manager session setting: - Log on to Fly Server Manager with an admin account. - On the Management >> General Settings page, click the "System Option" tab. - Set the session setting to "Session Will Expire After Inactivity for 10 minutes".

Identifiers

Group ID
V-283936
Group title
SRG-APP-000190
Rule ID
SV-283936r1206162_rule
Check ID
C-88501r1206160_chk
Fix ID
F-88406r1206161_fix