Skip to content
arrow_back
search
ISM-2066 policy ASD Information Security Manual (ISM)

Centralised Management of Web Application Sessions

Web apps use a server to handle and secure user sessions instead of relying on the user's device.

record_voice_over

Plain language

This control means that when you use a web application—like online banking or a shopping site—your session is managed and secured on the company's server rather than relying on just your computer or phone to keep the connection safe. This is important because if the session was managed only on your device, it might be easier for hackers to hijack your session and pretend to be you, possibly leading to unauthorised access to your accounts and sensitive information.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

May 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Web application sessions are centrally managed server side.
policy ASD Information Security Manual (ISM) ISM-2066
priority_high

Why it matters

Without centralised, server-side session management, attackers can more easily hijack sessions, gaining unauthorised access to web application data.

settings

Operational notes

Manage all web app sessions centrally on the server (avoid client-stored session state), rotate session IDs on login, and monitor for anomalous session reuse.

Mapping detail

Mapping

Direction

Controls