IA-11: Re-Authentication

NIST Baseline:  Low 

DIR Required By:  07/20/2023 

TAMUS Required By:  08/01/2022 

Review Date:  07/10/2024 

  • In addition to the re-authentication requirements associated with device locks, as described in Control AC-11, Device Lock, information resource owners may require re-authentication of individuals in certain situations, such as: 
    • When roles, authenticators, or credentials change, 
    • When security categories of systems change, 
    • When the execution of privileged functions occurs, or 
    • After a fixed time period. 
  • The lifetime of browser cookies used for binding authenticated sessions to university information resources shall be limited to no more than seven days. 
  • Workstations must be configured to automatically lock after 15 minutes of inactivity. 
  • Multifactor authentication must be configured to force reauthentication every five days or less. 

References/Additional Resources

None.  See any applicable internal procedures.