home/glossary/inactivity logout

inactivity logout

nounverified·updated Aug 30, 2026

A session-management security control that terminates an authenticated user's active session—fully ending the credential context rather than merely locking the screen—once the user has been, or is expected to be, idle for an organization-defined period. Within NIST SP 800-53, it is codified as control AC-2(5) in the Account Management family; in its policy-based form it requires users to take physical action to log out when they anticipate inactivity longer than the defined threshold. Logout is treated as stronger than screen lock because a locked workstation may preserve application sessions, whereas logout ends the session and typically clears session tokens and cookies. Across the field it is invoked as a compliance requirement under frameworks such as HIPAA and GDPR, as well as NIST-aligned programs, and in regulated environments such as 21 CFR Part 11 it is considered critical for audit-trail accuracy, access control, and session integrity.

MWELegacy lexicon import

Senses

NIST SP 800-171r3attested usage reviewer confirmed

No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.

Classifications

Entity Type

Control95%llm-generatedllm:claude-haiku-4-5
?unassignedlast reviewed

Sensitivity

Regulated90%rule-basedr:sens.regulated.framework.v1
?unassignedlast reviewed

Information Class

unclassified

Variants

plural
inactivity logouts
possessive
inactivity logout's
pluralpossessive
inactivity logouts'