HomeControl Library › 3.13.9
3.13 System & Communications Protection1 ptPOA&M-eligible

3.13.9 — Drop idle network sessions

Terminate network connections associated with communications sessions at the end of the sessions or after a defined period of inactivity.

Close network connections when a session ends or after a period of inactivity.

What it actually means

Network connections tied to a communications session should terminate at the end of the session or after a defined idle timeout — so abandoned sessions can't be hijacked. Practically, that means idle timeouts on your VPN, remote desktop, and any web application that handles CUI.

Pass or fail — an assessor needs a "yes" to each

What to have ready

Where teams trip up

See where this control puts your score

Run all 110 requirements free in about 10 minutes.

Calculate your SPRS score →

Connected requirements

← Back to the Control Library