SRG-APP-000223 Controls

STIG IDVersionTitleProduct
SRG-APP-000223-WSR-000011V4R4Cookies exchanged between the web server and client, such as session cookies, must have security settings that disallow cookie access outside the originating web server and hosted application.Security Requirements Guide - Web Server
SRG-APP-000223-WSR-000145V4R4The web server must accept only system-generated session identifiers.Security Requirements Guide - Web Server