inactivity logout
A session-management security control that terminates an authenticated user's active session—fully ending the credential context rather than merely locking the screen—once the user has been, or is expected to be, idle for an organization-defined period. Within NIST SP 800-53, it is codified as control AC-2(5) in the Account Management family; in its policy-based form it requires users to take physical action to log out when they anticipate inactivity longer than the defined threshold. Logout is treated as stronger than screen lock because a locked workstation may preserve application sessions, whereas logout ends the session and typically clears session tokens and cookies. Across the field it is invoked as a compliance requirement under frameworks such as HIPAA and GDPR, as well as NIST-aligned programs, and in regulated environments such as 21 CFR Part 11 it is considered critical for audit-trail accuracy, access control, and session integrity.