PCI DSS 8.2.8: If a user session has been idle for more than 15 minutes

PCI DSS v4.0.1 control 8.2.8: the requirement in full, the 1 testing procedure an assessor uses to verify it, and the related controls in section 8.2.

Requirement 8: Identify Users and Authenticate Access to System Components › Section 8.2

If a user session has been idle for more than 15 minutes, the user is required to re-authenticate to re-activate the terminal or session.

Summary

A session idle for more than 15 minutes requires the user to authenticate again.

What the assessor will examine

These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.

Procedure
8.2.8 Examine system configuration settings to verify that system/session idle timeout features for user sessions have been set to 15 minutes or less.

One of the few controls in Requirement 8 with a fixed number and no risk analysis to soften it: the procedure examines system configuration settings for a timeout of 15 minutes or less, so it is a value an assessor reads rather than a practice they discuss. Distinguish it from 9.2.4, which locks a physical console in a sensitive area. 8.2.8 is about the session, wherever it is, and that includes the browser-based administrative consoles that most often carry their own longer timeout set by whoever installed them. Re-authenticate is the operative word: dismissing a screensaver without entering credentials does not satisfy it.

What to prepare

  • Timeout settings for every in-scope system: operating systems, applications, administrative web consoles, jump hosts, database tools.
  • The policy stating the value, so the setting has something behind it.
  • Screenshots or configuration exports for the sample the assessor will pick.

How to implement it

1. Enumerate the administrative consoles. Cloud provider consoles, hypervisor managers, firewall interfaces and monitoring dashboards each carry their own timeout, and they are the ones set once at installation and never revisited.

2. Set it centrally where you can. Group policy or the equivalent covers the operating systems in one place and leaves you a much shorter list to handle individually.

3. Check that the lock demands credentials. A session that resumes on any keypress is idle-locked in appearance only.

4. Look for the remember-me option. A persistent session that survives idle time defeats the timeout underneath it, and it is usually a setting rather than a design decision.

Where this commonly fails

  • Operating systems configured by policy and applications left at their vendor defaults.
  • A timeout longer than 15 minutes on an administrative web console, which is the most common single finding for this control.
  • Keep-me-signed-in options that outlast the idle timeout.
  • A screensaver that locks the display without requiring re-authentication.

Others in section 8.2:

Control What it requires
8.2.1 All users are assigned a unique ID before access to system components or cardholder data…
8.2.2 Group, shared, or generic IDs, or other shared authentication credentials are only used…
8.2.3 Service providers with remote access to customer premises use unique authentication factors…
8.2.4 Addition, deletion, and modification of user IDs, authentication factors…
8.2.5 Access for terminated users is immediately revoked
8.2.6 Inactive user accounts are removed or disabled within 90 days of inactivity
8.2.7 Accounts used by third parties to access, support…

8.2.7 · All controls · 8.3.1

Source

The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.

The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.