IA-11 Re-Authentication
Description
The capability for information resources to uniquely identify and re-authenticate university faculty, staff, students, and other approved users.
Applicability
- This Control applies to all Texas A&M information resources. The intended audience for this Control includes all owners and custodians of information resources.
Implementation
-
1In addition to the re-authentication requirements associated with device locks (See AC-11), information resource owners may require re-authentication of individuals in certain situations, such as:
-
2The lifetime of browser cookies used for binding authenticated sessions to university information resources shall be limited to no more than five (5) days.