- Severity
- MODERATE
- Status
- IN PROGRESS
- Owner
- Digital Channels
- Root cause
- Configuration
- Test failure
- Design assessment (CDA)
- Opened
- 2026-03-20
- Due
- 2026-08-31
- Closed
- —
103 days old as of 2026-07-01
Session timeout enforcement differs between mobile operating systems.
PARTIAL
tested 2026-03-05
This issue records a CDA failure, shown first.
Control Design Assessment (CDA)
Procedures evaluating whether the control is designed adequately.
- 1.Inspect the mobile session configuration to confirm sessions are bound to a registered device identifier.
- 2.Confirm a session timeout is enforced and cannot be extended indefinitely by user activity alone.
Control Operating Effectiveness (COE)
Procedures evaluating whether the control operated over the testing period.
- 1.Attempt to replay a session token on an unregistered device and confirm access is denied.
- 2.Select 25 mobile sessions from the period and confirm each enforced the configured timeout.
- 3.Review configuration change logs to confirm device binding was not disabled during the period.
Related issues
Same root cause or a shared entity
- Prior pen test findings unresolvedCOEMODERATE
- Critical patch SLA misses on internet-facing serversCOECRITICAL
- IAM policy guardrails not enforced as codeCDAMODERATE
Score contribution
Issue-pressure points as of 2026-07-01, before the factor is capped at 0–100.
- Mobile Banking App12 of 92 pts
13% of this entity’s issue pressure
Annual priority score: 57 · issue pressure carries 10% weight in the active model — one factor among several behind that score.
- MODERATE severity: 12
Linked entities
- Mobile Banking App
APPLICATION · CRITICAL