NIST 800-171 Controls · System and Communications Protection
SC.2.009 — Terminate Sessions After Inactivity
Terminate network connections associated with communications sessions at the end of the sessions or after a defined period of inactivity.
What SC.2.009 means in plain English
When someone walks away from their computer or their VPN session sits idle, the connection should automatically end after a set period. This prevents someone from coming back to an unlocked session hours later — or worse, an attacker finding an active session on an unattended machine. Set VPN timeouts, web application session timeouts, and remote desktop timeouts to disconnect after 15-30 minutes of inactivity.
The assessment question
“Do your systems automatically terminate VPN connections, remote desktop sessions, and web application sessions after a defined period of inactivity (typically 15-30 minutes)?”
How to implement SC.2.009
- Configure Windows screen lock to activate after 15 minutes of inactivity: Settings > Personalization > Lock Screen > Screen timeout settings, or via Group Policy.
- Set VPN session timeout: in pfSense OpenVPN, set "Inactive" to 1800 seconds (30 minutes). In WireGuard, configure PersistentKeepalive and handle timeouts at the firewall level.
- For Remote Desktop sessions, configure idle timeout via Group Policy: Computer Configuration > Administrative Templates > Windows Components > Remote Desktop Services > Session Time Limits > set idle limit to 30 minutes.
- For web applications, configure session timeout in the application settings (most default to 20-30 minutes, verify this is enabled and not set to "never").
Evidence your assessor will ask for
- Group Policy or Windows Settings showing screen lock timeout of 15 minutes or less
- VPN configuration showing session idle timeout (30 minutes or less)
- Remote Desktop session timeout policy configuration screenshot
- Web application session timeout configuration evidence
Does AI prompt monitoring help with this control? Honestly, no.
SC.2.009 is met through the remediation steps above, not through AI traffic controls — an AI prompt firewall neither satisfies nor substitutes for it. We map AI monitoring only to the controls it genuinely evidences (flow control, boundary protection, audit, and incident support); for the full picture of where it does help, see the mapping guide linked below.
Full mapping: which 800-171 controls AI prompt monitoring evidences →
More System and Communications Protection controls
Monitor and Protect Communications at Boundaries
SC.1.005Implement Subnetworks for Public Components
SC.2.002Employ Effective Security Architecture
SC.2.003Separate User and System Management Functionality
SC.2.004Prevent Unauthorized Info Transfer via Shared Resources
SC.2.006Deny Network Traffic by Default
Score yourself against all 110 controls
The free ShieldReady assessment walks every NIST 800-171 requirement, computes your SPRS score, and shows exactly which gaps cost the most points.