Skip to content
arrow_back
search
ISM-2067 policy ASD Information Security Manual (ISM)

Ensure Single Logout for Single Sign-On Web Applications

Web apps with Single Sign-On should also log users out from all connected services.

record_voice_over

Plain language

When you log out of a system that uses Single Sign-On (SSO), this control ensures you are automatically logged out of all related services, not just the one you're leaving. This is important because if you forget to log out from multiple places, someone else might gain unauthorized access to your accounts, risking your company's sensitive information.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

May 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Web applications that support Single Sign On equally support Single Logout.
policy ASD Information Security Manual (ISM) ISM-2067
priority_high

Why it matters

Without Single Logout in SSO, ending a session in one app may not terminate sessions in other linked apps, enabling unauthorised access to organisational data.

settings

Operational notes

Verify SSO Single Logout ends IdP and all relying-party sessions; test browser/back-button and multi-tab scenarios after changes to SSO or app integrations.

Mapping detail

Mapping

Direction

Controls