{"data":{"id":"SC-10","name":"Network Disconnect","family":"SC","family_name":"System and Communications Protection","withdrawn":false,"description":"Terminate the network connection associated with a communications session at the end of the session or after [Assignment: organization-defined time period] of inactivity.","supplemental_guidance":"Network disconnect applies to internal and external networks. Terminating network connections associated with specific communications sessions includes de-allocating TCP/IP address or port pairs at the operating system level and de-allocating the networking assignments at the application level if multiple application sessions are using a single operating system-level network connection. Periods of inactivity may be established by organizations and include time periods by type of network access or for specific network accesses.","enhancements":[],"baseline_low":false,"baseline_moderate":true,"baseline_high":true,"nist_800_53":{"rev5":{"id":"SC-10","name":"Network Disconnect","description":"Terminate the network connection associated with a communications session at the end of the session or after [Assignment: organization-defined time period] of inactivity.","discussion":"Network disconnect applies to internal and external networks. Terminating network connections associated with specific communications sessions includes de-allocating TCP/IP address or port pairs at the operating system level and de-allocating the networking assignments at the application level if multiple application sessions are using a single operating system-level network connection. Periods of inactivity may be established by organizations and include time periods by type of network access or for specific network accesses.","related_controls":["AC-17","SC-23"],"baseline_low":false,"baseline_moderate":true,"baseline_high":true,"baseline_privacy":false,"new_in_rev5":false,"changes_from_rev4":""}},"compliance_mappings":{"iso_27001_2022":["A.8.20"],"iso_27002_2022":[],"cobit_2019":[],"pci_dss_v4":[],"nist_csf_2":[],"cis_controls_v8":[],"soc2_tsc":[],"finos_ccc":[],"iso_42001_2023":[],"iec_62443":[],"asd_e8":[],"nis2":[],"apra_cps_234":[],"mas_trm":[],"pra_op_resilience":[],"bsi_grundschutz":[],"anssi":["Hygiene.12","SecNumCloud.10.6"],"osfi_b13":["B-13.3.2"],"finma_circular":["IV.B.d(59)","IV.C(61)"],"gdpr":["Art.32(1)(b)"],"dora":["Art.9(4)(c)"],"bio2":[],"rbi_csf":["Annex1.8"],"fisc":[],"lgpd_bcb":[],"hkma_tme1":["TME1.8.4"],"mlps_2":[],"dnb_good_practice":[],"cra":[],"swift_cscf":[],"cbb_tm":["TM-8"],"nca_ecc":["2-5"],"qatar_nia":["CS"],"sama_csf":["3.8"],"uae_ia":["T8"],"bcbs_239":["Principle 5"],"bot_cyber":["Ch2.4"],"eba_ict":["3.4.2"],"ffiec_is":["II.C.6","II.C.9","II.C.15(c)"],"hipaa_sr":["§164.312(a)(2)(iii)"],"cmmc_2":["SC"],"nerc_cip":[],"nrc_73_54":[],"tsa_psd":[],"ieee_1686":["5.8"],"ferc_cip":[],"doe_c2m2":[],"api_1164":[],"awia":[],"iaea_nss":[],"pci_pts":[],"fips_140":[],"cbest":[],"tiber_eu":[],"pci_hsm":[],"common_criteria":["CC Part 2 — FRU/FTA/FTP"],"isae_3402":[],"fca_sysc_13":[],"fda_21_cfr_11":["§11.200(a)(1)(i)"],"fda_cyber":[],"hitrust_csf":["01.b"],"iso_27799":["9.5"],"lloyds_ms":[],"naic_ds":[],"nhs_dspt":[],"pra_ss1_23":[],"solvency_ii":[],"owasp_masvs_v2":[],"csa_ccm_v4":[],"csa_aicm":[],"ccss_v9":[],"mica":[],"basel_sco60":[],"bssc":[],"sec_custody_digital":[],"dpdpa":[]},"attack_techniques":[{"id":"T1071","name":"Application Layer Protocol","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Automatic network disconnection after session timeouts terminates adversary command-and-control channels that rely on persistent application-layer protocol connections."},{"id":"T1071.001","name":"Web Protocols","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Network disconnect after session timeout terminates HTTP/HTTPS-based C2 channels, forcing adversaries to re-establish web protocol connections and increasing detection opportunities at reconnection."},{"id":"T1071.002","name":"File Transfer Protocols","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Automatic disconnection of idle file transfer protocol sessions terminates adversary FTP/SFTP-based data exfiltration channels, requiring new session establishment for continued data transfer."},{"id":"T1071.003","name":"Mail Protocols","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Network disconnect on idle mail protocol sessions terminates SMTP/IMAP-based C2 and exfiltration channels, preventing adversaries from maintaining persistent email protocol connections for covert communication."},{"id":"T1071.004","name":"DNS","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Automatic disconnection of persistent DNS connections terminates DNS-based C2 tunnels, forcing adversaries to re-establish DNS communication channels and generating detectable reconnection patterns."}],"metadata":{"last_reviewed":"2026-10-03","review_notes":"2026-10-02: iso_27001_2022 clauses taken from NIST's SP 800-53 Rev 5 to ISO/IEC 27001:2022 crosswalk (OLIR, v1.0.0). OSA had none. 2026-10-03: baselines LMH to -MH, from NIST SP 800-53B Release 5.2.0.","mapping_status":"complete"},"function":"preventative","used_by_patterns":["SP-002","SP-016"]}}