STIGQter STIGQter: STIG Summary: Virtual Private Network (VPN) Security Requirements Guide Version: 3 Release: 5 Benchmark Date: 01 Jul 2026:

The Remote Access VPN Gateway must terminate remote access network connections after an organization-defined time period.

DISA Rule

SV-251044r971530_rule

Vulnerability Number

V-251044

Group Title

SRG-NET-000213

Rule Version

SRG-NET-000213-VPN-000721

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

This SRG requirement is in response to the DoD OIG Audit of Maintaining Cybersecurity in the Coronavirus Disease-2019 Telework Environment. VPN connections that provide user access to the network are the prime candidates for VPN session termination and are the primary focus of this requirement.

Conduct a risk assessment to identify the use case for the VPN and determine if periodic VPN session termination puts the mission at risk of failure.

Identify the organizations' VPN session termination periodic value based on the risk assessment. Add the results of the risk assessment and the session termination values to the site's SSP documents.

Configure the VPN gateway to periodically terminate all remote network connections in accordance with the values defined in the SSP.

Check Contents

This SRG requirement is in response to the DoD OIG Audit of Maintaining Cybersecurity in the Coronavirus Disease-2019 Telework Environment. VPN connections that provide user access to the network are the prime candidates for VPN session termination and are the primary focus of this requirement.

Review the system security plan. Verify the VPN gateway session termination is configured in accordance with the value specified in the SSP.

If a risk assessment has not been conducted and an organization-defined session termination period is not addressed/documented in the SSP, this is a finding.

If the VPN gateway is not configured to terminate all remote access network connections in accordance with the values defined in the SSP, this is a finding.

Vulnerability Number

V-251044

Documentable

False

Rule Version

SRG-NET-000213-VPN-000721

Severity Override Guidance

This SRG requirement is in response to the DoD OIG Audit of Maintaining Cybersecurity in the Coronavirus Disease-2019 Telework Environment. VPN connections that provide user access to the network are the prime candidates for VPN session termination and are the primary focus of this requirement.

Review the system security plan. Verify the VPN gateway session termination is configured in accordance with the value specified in the SSP.

If a risk assessment has not been conducted and an organization-defined session termination period is not addressed/documented in the SSP, this is a finding.

If the VPN gateway is not configured to terminate all remote access network connections in accordance with the values defined in the SSP, this is a finding.

Check Content Reference

M

Target Key

2920