Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
03.01.11OFFICIAL TITLEPENDING NIST SME REVIEW

03.01.11Session Termination

03.01 Access Control · NIST SP 800-171 Rev. 3

Independent summary of the official requirement

Requires automatically terminating a user session after organization-defined conditions or trigger events requiring session disconnect (aligned to SP 800-53 AC-12). Termination ends the logical session itself, as distinct from locking the device display.

Rev. 3 requirement text is multi-part and parameterized with organization-defined values, so this site summarizes rather than reproduces it. The summary is independent — read the official publication for the binding wording.

NIST SP 800-171 Rev. 3 — Protecting CUI in Nonfederal SystemsNIST SP 800-171A Rev. 3 — Assessing Security Requirements for CUI
Independent interpretation

What this requirement is after

A lock hides the screen; termination ends the session. You define the events that kill a session outright — idle time on a VPN, an admin console left open overnight, a risk signal from the identity platform — and the system enforces them. The concrete wins for a small contractor are VPN idle disconnects and bounded admin-portal session lifetimes.

Mapped practices

Brilliant at the Basics practices that support this requirement

Doing the work

Implementation considerations and evidence

Implementation considerationsIndependent guidance — tailor to your environment
  • Choose and document trigger conditions per access type — remote sessions, admin consoles, and web sessions deserve different lifetimes.
  • Configure idle and maximum session lifetimes in the VPN or ZTNA platform, the identity provider, and the admin planes.
  • Verify termination invalidates the session token, not just the visible window; a reusable token defeats the point.
What operating evidence looks likeRecords worth retaining, not a submission checklist
  • Session-lifetime and disconnect configuration for remote access and admin surfaces
  • Logs showing sessions terminated on the defined conditions
Artifacts

Templates and worksheets with a mapped relationship

No artifact in the library names this requirement yet. The library index groups everything by category and practice.

The other revision

Where this came from in Rev. 2

Provenance

Sources and review status

Primary sourcesNIST SP 800-171 Rev. 3 — Protecting CUI in Nonfederal Systems · NIST SP 800-171A Rev. 3 — Assessing Security Requirements for CUI
Review statusPending NIST SME review
Content version1.0
Updated