SC-10 Network disconnect
Requires the network connection behind a communications session to be terminated when the session ends or after an organization-defined period of inactivity, rather than left established once it is no longer in use.
4
artefacts
2
held by a system
1
at each review
easy
to go live
Endpoint management (MDM / EDR)
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Device and application configuration enforcing session and connection termination · Endpoint management (MDM / EDR)
- Sample logs showing idle connections being closed · SIEM / log platform
periodic reviewEvidence produced at each review
- Coverage evidence across remote access, administrative and application sessions · Document repository
governing documentDocuments that govern the control
- Documented inactivity period for network disconnection · Policy repository / GRC workspace
First move
Automate the pull from your Endpoint management (MDM / EDR). Device compliance report from the MDM (encryption, EDR agent, OS version) on a daily pull.
Common gaps auditors find
- Application session ends while the underlying network connection stays open
- Inactivity period never defined, leaving vendor defaults measured in hours
- Administrative sessions to network devices exempt from any timeout
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetSC-8 Transmission confidentiality and integrity · SC-11 Trusted Path. Provide a [organization-defined] isolated trusted communications path for communications between the user and the trusted components of the system; and Permit users to invoke the trusted communications path for communications between the