Beyond CMMC Level 1
The free web app covers the 17 CMMC Level 1 practices. This requirement is part of the full NIST 800-171 set — get the desktop app to work on all 110 requirements with SPRS scoring. Previously saved data is shown read-only below, and your data always remains exportable in full.
Get the desktop appSecurity Requirements for 03.13.09 Connections Termination
This requirement applies to internal and external networks. Terminating network connections associated with communications sessions include de-allocating associated TCP/IP address or port pairs at the operating system level, or de-allocating networking assignments at the application level if multiple application sessions are using a single, operating system-level network connection. Time periods of user inactivity may be established by organizations and include time periods by type of network access or for specific network accesses.
Assessment GuidanceExamine 0/7
How an assessor determines this requirement is met. Source: CMMC Assessment Guide – Level 2, Version 2.13 (NIST SP 800-171 Rev. 2).
Discussion
Prevent malicious actors from taking advantage of an open network session or an unattended computer at the end of the connection. Balance user work patterns and needs against security to determine the length of inactivity that will force a termination.
This requirement, SC.L2-3.13.9, specifies network connections be terminated under certain conditions, which complements AC.L2-3.1.18 that specifies control of mobile device connections.
Examples
- Example 1
You are an administrator of a server that provides remote access. Your company’s policies state that network connections must be terminated after being idle for 60 minutes [a]. You edit the server configuration file and set the timeout to 60 minutes and restart the remote access software [c]. You test the software and verify that the connection is terminated appropriately.
Assessment Methods
Not all of the evidence listed is required to meet this requirement — check the items your organization has collected.
- System or network administrators
- Personnel with information security responsibilities
- System developer
- Mechanisms supporting or implementing network disconnect capability