SV-251044r971530_rule
V-251044
SRG-NET-000213
SRG-NET-000213-VPN-000721
CAT II
10
This SRG requirement is in response to the DoD OIG Audit of Maintaining Cybersecurity in the Coronavirus Disease-2019 Telework Environment. VPN connections that provide user access to the network are the prime candidates for VPN session termination and are the primary focus of this requirement.
Conduct a risk assessment to identify the use case for the VPN and determine if periodic VPN session termination puts the mission at risk of failure.
Identify the organizations' VPN session termination periodic value based on the risk assessment. Add the results of the risk assessment and the session termination values to the site's SSP documents.
Configure the VPN gateway to periodically terminate all remote network connections in accordance with the values defined in the SSP.
This SRG requirement is in response to the DoD OIG Audit of Maintaining Cybersecurity in the Coronavirus Disease-2019 Telework Environment. VPN connections that provide user access to the network are the prime candidates for VPN session termination and are the primary focus of this requirement.
Review the system security plan. Verify the VPN gateway session termination is configured in accordance with the value specified in the SSP.
If a risk assessment has not been conducted and an organization-defined session termination period is not addressed/documented in the SSP, this is a finding.
If the VPN gateway is not configured to terminate all remote access network connections in accordance with the values defined in the SSP, this is a finding.
V-251044
False
SRG-NET-000213-VPN-000721
This SRG requirement is in response to the DoD OIG Audit of Maintaining Cybersecurity in the Coronavirus Disease-2019 Telework Environment. VPN connections that provide user access to the network are the prime candidates for VPN session termination and are the primary focus of this requirement.
Review the system security plan. Verify the VPN gateway session termination is configured in accordance with the value specified in the SSP.
If a risk assessment has not been conducted and an organization-defined session termination period is not addressed/documented in the SSP, this is a finding.
If the VPN gateway is not configured to terminate all remote access network connections in accordance with the values defined in the SSP, this is a finding.
M
2920