The session time out is the server default of 24 minutes ...
You want to be careful on changing this as if 24 minutes has passed ... is the customer really still at the computer in the coffee shop or library? Or did they walk away?
If they have not clicked a link in 24 minutes, they could just log back in again ... if they are not there ... then you prevented some person of evil intent from getting into their information because they did not close down the browser etc.



