ASVS
ASVS copied to clipboard
3.3.5 - Update to correspond updated 3.3.2
Following from #2113 and related to #2076, I propose the following update for 3.3.5:
| # | Description | L1 | L2 | L3 | CWE | NIST § |
|---|---|---|---|---|---|---|
| 3.3.5 | [ADDED, SPLIT FROM 3.3.2] Verify that there is an inactivity timeout such that re-authentication is enforced according to risk analysis and documented security decisions. | ✓ | ✓ | ✓ |
Ok for me, let's PR it in.
Updated via #2202