CMMC 1.0 Practice SC.3.186 Requirement:

Terminate network connections associated with communications sessions at the end of the sessions or after a defined period of inactivity.

CMMC 1.0 SC.3.186 Requirement Explanation:

By terminating inactive sessions you reduce the risk of attackers taking advantage of them.

Example CMMC 1.0 SC.3.186 Implementation:

Establish a policy specifying the period of inactivity before a network connection is terminated. An example is 60 minutes. This can be implemented on your firewall by setting the idle time out settings (e.g., in seconds: UDP = 5, TCP = 1800, ICMP = 5, Other = 180). The same can be applied to your VPN connections.

CMMC 1.0 SC.3.186 Scenario(s):

- Scenario 1:

You have a VPN appliance allowing users to connect to your network. You configure the idle time out on the VPN to meet your policy which is 60 minutes.

Discover Our NIST SP 800-171 & CMMC 2.0 Solutions:


Compliance Accelerator

Power through compliance. Meet and maintain your NIST SP 800-171 & CMMC 2.0 compliance requirements.

Quantum Assessor

Transform your business. Create new revenue streams and provide scalability for your NIST SP 800-171 and CMMC 2.0 services.

Supply Chain Verifier

Trust is everything. Verify, monitor, and support subcontactor compliance.