Skip to main content
MuonPartners
Services
Architecture

Solution design and technology roadmapping

Solution AssessmentTechnology RoadmapsIntegration DesignSolution ArchitectureTechnical Design
Cyber Security

Security assessments, IAM, and compliance

AssessmentsIAMComplianceSecurity BaselineCyber Innovation
Network and Platform

Network architecture and cloud platforms

Network DesignCloud StrategyModernisation
Enterprise Architecture

Business-technology alignment

Business AlignmentPortfolio AnalysisGovernance
View all services
ProjectsCase StudiesInsightsToolsAbout
Contact Us

Services

Architecture
Solution AssessmentTechnology RoadmapsIntegration DesignSolution ArchitectureTechnical Design
Cyber Security
AssessmentsIAMComplianceSecurity BaselineCyber Innovation
Network and Platform
Network DesignCloud StrategyModernisation
Enterprise Architecture
Business AlignmentPortfolio AnalysisGovernance
ProjectsCase StudiesInsightsToolsAboutContact
Get in Touch
MuonPartners

Strategic technology consulting for Australian organisations navigating complexity.

Services

  • Architecture
  • Cyber Security
  • Network and Platform
  • Enterprise Architecture

Company

  • About
  • Products
  • Frameworks
  • Cross-Framework Mapping
  • Projects
  • Case Studies
  • Insights
  • Contact

Contact

  • [email protected]
  • Australia
  • LinkedIn

© 2026 Muon Partners. All rights reserved.

ABN 50 669 022 315 · A Muon Group company.

Privacy PolicyTerms of Service
  1. Frameworks
  2. >ISM
  3. >Software Development
  4. >Web Application Development
  5. >Secure Web Application Design And Development
  6. >ISM-2065
ISM-2065Active

Control: ism-2065

Control Statement

Web application session cookies using opaque bearer tokens that are not digitally signed use non-sequential random identifiers with a minimum of 128 bits of entropy, preferably 256 bits of entropy.

Location

Guideline
Guidelines for software development
Section
Web application development
Topic
Secure web application design and development

Control Details

Identifier
ISM-2065
Revision
0
Updated
Jun-25
Type
Control

Classification Applicability

NCOSPSTS

Essential Eight

N/A

No cross-framework mappings available

← Back to Secure web application design and development
Secure web application design and development9 controls
ISM-1239Control: ism-1239ISM-0971Control: ism-0971ISM-1849Control: ism-1849ISM-1850Control: ism-1850ISM-2063Control: ism-2063ISM-2064Control: ism-2064ISM-2065Control: ism-2065ISM-2066Control: ism-2066ISM-2067Control: ism-2067