Under active development Content is continuously updated and improved

SC-10Network Disconnect

PBMM (P3)
Secret (P3)
Technical

>Control Description

(A) The information system terminates the network connection associated with a communications session at the end of the session or after organization-defined time period of inactivity.

>Supplemental Guidance

This control applies to both internal and external networks. Terminating network connections associated with communications sessions include, for example, de-allocating associated TCP/IP address/port pairs at the operating system level, or de-allocating networking assignments at the application level if multiple application sessions are using a single, operating system-level network connection. Time periods of inactivity may be established by organizations and include, for example, time periods by type of network access or for specific network accesses

>Tailoring Guidance

This security control/enhancement can be met using readily available Commercial-Off-The-Shelf (COTS) components. Consequently, inclusion in a departmental profile is strongly encouraged in most cases. The security control/enhancement refers to user sessions such as Web sessions or client VPN sessions.

Firewalls will automatically drop TCP/IP sessions after a certain period of inactivity.

Ask AI

Configure your API key to use AI features.