Control statement
Require users to re-authenticate when {{ insert: param, ia-11_odp }}.
Guidance: The fixed time period cannot exceed the limits set in SP 800-63. At this writing they are:
* AAL2 (moderate baseline) * 12 hours or * 30 minutes of inactivity Parameter placeholders {{ insert: param, … }} reference FedRAMP-set values in the resolved profile. Full parameter map is
preserved in the catalog database.
Covered by these Key Security Indicators
| KSI | Title | Category |
|---|---|---|
| KSI-IAM-05 | Least Privilege _Persistently_ ensure that identity and access management employs measures to ensure each user or device can only access the resources they need. | Identity and Access Management |