Lack of network connection controls over communications sessions may result in unauthorized access to information systems
The information system terminates the network connection associated with a communications session at the end of the session or after [Assignment: organization-defined time period] of inactivity.
Network connections are automatically disabled after a set time of inactivity.
No statewide control
Obtain system and communications protection policy; procedures addressing network disconnect; information system design documentation; organization-defined time period of inactivity before network disconnect; information system configuration settings and associated documentation; other relevant documents or records and ascertain if :
(I)the organization defines in the security plan, explicitly or by reference, the time period of inactivity before the information system terminates a network connection.
(ii)the information system terminates a network connection at the end of a session or after the organization-defined time period of inactivity.