Ensure session disconnect timeout is set to 5 minutes or less (Automated)
Profile Applicability
- Level 1
Description
Disconnect timeout in minutes, is the amount of of time that a streaming session remains active after users disconnect.
Rationale
If users try to reconnect to the streaming session after a disconnection or network interruption within the 5 minutes, they are connected to their previous session. Otherwise, they are connected to a new session with a new streaming instance and that instance isn't sitting out there not being used.
Impact
None - this is a security best practice.
Audit Procedure
Perform the following steps to view the Fleet settings in AppStream.
Using AWS Console
- Log in to the AppStream 2.0 console at
https://console.aws.amazon.com/appstream2 - In the left pane click on Fleets
- Select the link for the fleet name you wish to view
- On the Fleet configuration section confirm that Disconnect timeout is set to 5 minutes or less
If Disconnect timeout is set to anything greater than 5 minutes refer to the remediation below.
Using AWS CLI
Not applicable - must be audited via Console.
Expected Result
Disconnect timeout is set to 5 minutes or less.
Remediation
Using AWS Console
Perform the following steps to update the Fleet settings in AppStream:
- Log in to the AppStream 2.0 console at
https://console.aws.amazon.com/appstream2 - In the left pane click on Fleets
- Select the link for the fleet name you wish to edit
- Scroll to the Fleet configuration section and click Edit
- Change the Disconnect timeout to 5 minutes or less
Using AWS CLI
Not applicable - must be configured via Console.
Default Value
By default, AWS Appstream 2.0 session disconnect time is set to 15 minutes.
References
- https://docs.aws.amazon.com/appstream2/latest/developerguide/set-up-stacks-fleets.html
- https://us-east-1.console.aws.amazon.com/appstream2/home?region=us-east-1#/create-fleet
CIS Controls
v8:
- 0.0 Explicitly Not Mapped
v7:
- 0.0 Explicitly Not Mapped
Profile
Level 1