EvidenceSheet

SC-10 Network disconnect

Requires the network connection behind a communications session to be terminated when the session ends or after an organization-defined period of inactivity, rather than left established once it is no longer in use.

4
artefacts
2
held by a system
1
at each review
easy
to go live
Endpoint management (MDM / EDR)
where the evidence lives
teal = a system already holds it · olive = produced at each review

system holds itEvidence a system already holds

  • Device and application configuration enforcing session and connection termination · Endpoint management (MDM / EDR)
  • Sample logs showing idle connections being closed · SIEM / log platform

periodic reviewEvidence produced at each review

  • Coverage evidence across remote access, administrative and application sessions · Document repository

governing documentDocuments that govern the control

  • Documented inactivity period for network disconnection · Policy repository / GRC workspace

First move

Automate the pull from your Endpoint management (MDM / EDR). Device compliance report from the MDM (encryption, EDR agent, OS version) on a daily pull.

Common gaps auditors find

Do this for your whole sheet

Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.

Build my evidence sheet

SC-8 Transmission confidentiality and integrity · SC-11 Trusted Path. Provide a [organization-defined] isolated trusted communications path for communications between the user and the trusted components of the system; and Permit users to invoke the trusted communications path for communications between the