SC-10-727 Network Disconnect

System and Communications Protection
System Communications Protection
Lack of network connection controls over communications sessions may result in unauthorized access to information systems
The information system terminates the network connection associated with a communications session at the end of the session or after [Assignment: organization-defined time period] of inactivity.
Network connections are automatically disabled after a set time of inactivity.
No statewide control
Obtain system and communications protection policy; procedures addressing network disconnect; information system design documentation; organization-defined time period of inactivity before network disconnect; information system configuration settings and associated documentation; other relevant documents or records and ascertain if : (I)the organization defines in the security plan, explicitly or by reference, the time period of inactivity before the information system terminates a network connection. (ii)the information system terminates a network connection at the end of a session or after the organization-defined time period of inactivity.