Configure session persistence to minimise fixation and hijacking risks.
Networking / Loadbalancer / Controls / DEV
Validate Session Affinity
CCC.LB.CN05 · Networking
Related Capabilities
| ID | Title | Description |
|---|---|---|
| CCC.LB.CP15 | Session Affinity | Can configure subsequent requests from an initial client to be passed to the same target. |
Related Threats
| ID | Title | Description |
|---|---|---|
| CCC.LB.TH04 | Session Persistence Is Exploited | Improper session-affinity settings can enable session fixation or hijacking across backend targets. |
Assessment Requirements
| ID | Text | Applicability |
|---|---|---|
| CCC.LB.CN05.AR01 | When stickiness is enabled, session cookies MUST expire within 30 minutes of inactivity. | tlp-green, tlp-amber, tlp-red |