Overview

Security Requirements for 03.13.09 Connections Termination

This requirement applies to internal and external networks. Terminating network connections associated with communications sessions include de-allocating associated TCP/IP address or port pairs at the operating system level, or de-allocating networking assignments at the application level if multiple application sessions are using a single, operating system-level network connection. Time periods of user inactivity may be established by organizations and include time periods by type of network access or for specific network accesses.

Evidence

  1. 03.13.09.a

    A period of inactivity to terminate network connections associated with communications sessions is defined

  1. 03.13.09.b

    Network connections associated with communications sessions are terminated at the end of the sessions

  1. 03.13.09.c

    Network connections associated with communications sessions are terminated after the defined period of inactivity