From Help:
The default value of 12 hours for absolute session timeout is aligned with the National Institute of Standards and Technology (NIST) Digital Identity Guidelines for Authentication and Lifecycle Management. Click here to view Section 4.2.3, Reauthentication, in the NIST guidelines.