NIST 800-171 Controls · System and Communications Protection

SC.2.009Terminate Sessions After Inactivity

CMMC Level 2SPRS if unmet: -1LOW priority~3h to implement

Terminate network connections associated with communications sessions at the end of the sessions or after a defined period of inactivity.

What SC.2.009 means in plain English

When someone walks away from their computer or their VPN session sits idle, the connection should automatically end after a set period. This prevents someone from coming back to an unlocked session hours later — or worse, an attacker finding an active session on an unattended machine. Set VPN timeouts, web application session timeouts, and remote desktop timeouts to disconnect after 15-30 minutes of inactivity.

The assessment question

Do your systems automatically terminate VPN connections, remote desktop sessions, and web application sessions after a defined period of inactivity (typically 15-30 minutes)?

How to implement SC.2.009

  1. Configure Windows screen lock to activate after 15 minutes of inactivity: Settings > Personalization > Lock Screen > Screen timeout settings, or via Group Policy.
  2. Set VPN session timeout: in pfSense OpenVPN, set "Inactive" to 1800 seconds (30 minutes). In WireGuard, configure PersistentKeepalive and handle timeouts at the firewall level.
  3. For Remote Desktop sessions, configure idle timeout via Group Policy: Computer Configuration > Administrative Templates > Windows Components > Remote Desktop Services > Session Time Limits > set idle limit to 30 minutes.
  4. For web applications, configure session timeout in the application settings (most default to 20-30 minutes, verify this is enabled and not set to "never").

Evidence your assessor will ask for

  • Group Policy or Windows Settings showing screen lock timeout of 15 minutes or less
  • VPN configuration showing session idle timeout (30 minutes or less)
  • Remote Desktop session timeout policy configuration screenshot
  • Web application session timeout configuration evidence

Does AI prompt monitoring help with this control? Honestly, no.

SC.2.009 is met through the remediation steps above, not through AI traffic controls — an AI prompt firewall neither satisfies nor substitutes for it. We map AI monitoring only to the controls it genuinely evidences (flow control, boundary protection, audit, and incident support); for the full picture of where it does help, see the mapping guide linked below.

Full mapping: which 800-171 controls AI prompt monitoring evidences →

More System and Communications Protection controls

Score yourself against all 110 controls

The free ShieldReady assessment walks every NIST 800-171 requirement, computes your SPRS score, and shows exactly which gaps cost the most points.