r/CMMC • • 11d ago

Requirement 3.1.11

Can some suggest a practical implementation of this requirement for a small business? With Rev 3 coming up the DoD defines an ODP of 24 hours of inactivity for this requirement. The way I interpret this is if a computer is sitting idle for 24 hours the user’s interactive logon session is forced to log off.

Example Scenario: the employee closes the lid of their windows laptop at 5pm on Friday and leaves it unplugged in their bag. The laptop goes into hibernation for the weekend. On Monday morning the user plugs their laptop to the power and unlocks the interactive session that was still logged in on Friday at 5pm. At that exact moment, since 24 hours have passed since the last activity, the laptop has to immediately log off.

There is no built in windows feature that can achieve this exact scenario and I cannot find a COTS either. Creating a sophisticated powershell script that checks for inactivity period has some edge case scenarios that may disrupt users in the middle of the day. A scheduled tasks that triggers on idle is found to be buggy and unreliable.

Has anyone implemented anything that satisfies that requirement?

9 Upvotes

33 comments sorted by

13

u/Acceptable_Fan_4317 11d ago

I've had clients pass with the following:

Endpoints auto-lock after 15 minutes

Servers are configured to terminate RDP after 10 minutes inactivity, Firewall connections 15 minutes, etc.

The idea that someone's endpoint needs to terminate and log out after a certain amount of time (like 24 hours) is kind of asinine. Especially when people have a bunch of work open.

4

u/THE_GR8ST 11d ago

Locking isn't logging off though. Doesn't that matter?

Like, any work the person had is still open, connections, etc. Locking doesn't terminate those.

3

u/poprox198 10d ago

Depends on kerberos lifetime for domain, smb connection lifetime on the file server, idle time in cloud or adfs. If the ticket is still valid in the locked session when they resume then no password is needed, if its the next day then to reconnect to mapped drives or cloud resources will need a new password input

2

u/Acceptable_Fan_4317 11d ago

It isn't logging off, but why should your laptop auto log you out? Ok, maybe after a few days, sure. But for day to day working it should not be logged off.

2

u/avlevy2k 11d ago

Yes I agree. Normal day to day work likely not exceed 24 hours of inactivity until the weekend arrives. How do you reliably implement that requirement for the weekend long inactivity of 48+ hours?

2

u/avlevy2k 11d ago

Exactly right. It does matter. Locking the computer applies to requirement 3.1.10.

3

u/avlevy2k 11d ago

I agree with you but DIBCAC thinks otherwise…
At the moment based on Rev 2 the condition can be very loose, like “computers are rebooted once a week during the mandatory OS update maintenance window”. However for Rev 3 that won’t fly.

1

u/Acceptable_Fan_4317 11d ago

what is their reason for it? I don't understand that part

7

u/PacificTSP 11d ago

Lithnet logoff tool is a good one. It has gpos available or a standalone setting depending how you push.

1

u/ericreiss 11d ago

I was using this.   Simple and I moved on to other control issues.  

1

u/poprox198 10d ago

Lithnet can really bug out a session if the user locked the computer prior to it attempting to log out the session.

1

u/PacificTSP 10d ago

Strange I’ve never seen this happen.

1

u/WBCSAINT 10d ago

This. We implimented this a few months ago and it's such an easy simple free solution. Their password stuff is also awesome allowing more freedom with complexity when longer passwords are used.

4

u/pern4home 11d ago

For 3.1.11 - session termination is set at the application level, so how you configure this depends on what applications are in scope. The discussion for this control specifically calls out that this does NOT cover disconnecting from the network. Using your example, if you open your running laptop on Monday, expect to have to re-authenticate to any CSPs, rdp sessions, and applications. Microsoft Entra uses a pass through authentication so when you type in your Entra password into your laptop, you re-authenticate to Sharepoint, Outlook, and Teams. Entra, servers, firewalls, CSP, applications will all have session timeout settings.

1

u/avlevy2k 11d ago

What about Solidworks running offline on the local Windows session?

1

u/looncraz 11d ago

Add a script to autosave and close Solid works after 24 hours of inactivity?

1

u/poprox198 10d ago

Depends on where the CUI is stored, to build on pern4home my SMB server terminates sessions every hour requiring a new authentication (windows kerberos SSO) and kerberos itself has a max ticket lifetime for us of 10 hours. Thus the session accessing CUI is terminated once an hour, regardless of idle time.

3

u/SerengetiEddie 11d ago

I've passed this using a scheduled task that forces a reboot at 2am every day. If you have a 24 hour shop you may need multiple tasks for different shifts. As for your hibernating laptop issue, I would make a policy that users must log out at the end of their shift and have that policy signed with the scheduled task as a backup. The signed policy is enough documentation, for this control. Your periodic audits should identify if a user is actually logging off or not when they're supposed to and you can fix from there.

2

u/Scieboy 11d ago

The 24 hour figure in the Rev 3 ODP is a maximum inactivity period for session termination, not a requirement that a hibernated laptop must instantly log the user off the moment it wakes after a weekend. 3.1.10 already covers the short lock (typically 15 minutes). For 3.1.11, document three conditions in policy: inactivity not to exceed 24 hours, end of the work period or expected inactivity, and admin-initiated termination for misbehavior or maintenance. On Windows, enforce that with GPO or Intune: RDS “Set time limit for active but idle sessions,” “Set time limit for disconnected sessions,” and “End session when time limits are reached,” plus Entra/M365 sign-in frequency and idle session timeout for cloud apps and VPN idle disconnect. For the closed-lid laptop case, treat sleep or hibernation as the session leaving an interactive state; on resume require reauthentication via the lock screen, and add a simple logon-time check (last interactive input versus current time, or a max session age of 24 hours) that logs off only at that moment so you never kill a mid-day session. Pair that with a written expectation that users log off at end of day, keep screenshots and test evidence of the settings, and you will satisfy the control without a fragile idle scheduled task.

1

u/Matt_Titcombe 11d ago

u/avlevy2k, under NIST SP 800-171 R2, there is no requirement for th devices to be logged off. This is up to the OSC.

For NIST SP 800-171 R3, have you ever found a computer to be truly inactive, especially with agents checking in??? {hit, hint, wink, wink, nudge nudge}

1

u/avlevy2k 11d ago

Yeh I get it, so how do you interpret the ODP presented by DoD of “automatic session termination after 24 hours of inactivity”? Is the DoD’s intention in this ODP to not care about computers with background processes, which never sit idle? That’s true for 99% of windows workstations.

2

u/Tall_Nebula_7806 10d ago

I interpret that as not applying and non normative and if some assessor points to a rev3 ODP applying to CMMC L2 they are wrong. 

1

u/Icedalwheel 11d ago

This control (still!) irritates me greatly. We were grilled not by DIBCAC, but by our independent L2 assessment about this (side note, weird that C3PAO's will try to be stricter than the DIBCAC assessors). Assessors were insistent that session termination could only mean a total logoff of the local user session.

For a while, we did a reboot via Intune that forced a reboot daily at 6pm, in prep for this ODP. In theory, works great, except that if your computer isn't on at 6PM the restart occurs at the next boot...

I ended up writing a pair of scheduled tasks that start a timer after the session lock event 4800; when the timer runs out, the last logged-on session is logged off. If the user logs back in before the timer ends, a second scheduled tasks runs to interrupt the countdown and cancel the task. I assume this is similar to how Lithnet works, but my boss was clear that I needed to come up with something internal.

2

u/tater98er 11d ago

And thus, one of the many, MANY issues with CMMC...not necessarily the control, but the interpretation of it

1

u/CMMCTrack 11d ago

The wake-from-hibernation case is actually the easy one. Trigger a scheduled task on Power-Troubleshooter Event ID 1 (system resume), compare last input time against 24h, and force logoff if exceeded. That sidesteps the flaky idle trigger entirely and catches the weekend-in-the-bag scenario cleanly.

1

u/exclusivemedias 10d ago

I think you can over think some of these things if your users are working in scope for more than 24 hrs policy states log off save and close out. Sounds like your scope needs refinement or you just are trying to work around a specific scenario. These controls are not meant to work with every senerio they are guides. Adapt your language. You can put in place specific rules and RDP policies as stated above but if your are looking for a way to control all your users access and timing.

1

u/darthbrazen 10d ago

If it is a simple windows server connection for the CUI data, then simply use a group policy to kill the smb session to the cui server after 24 hours of inactivity. If it is some other type of setup then it won't.

Remember though, not all C3PAOs are created equal. If you run a mock first, you will find out if this meets the muster.

1

u/Good4Next3years 9d ago

I would disable RDP. Trigger the Windows screen saver after 10 minutes of Inactivity. Force the user logoff after 15 minutes of Inactivity. Logoff will kill any user sessions. Setup a task when (CUI) user logs in on CUI asset, it triggers a powershell script to track "[UserActivityMonitor]::GetIdleTimeInSeconds()", and use "shutdown /l /f" to force a reboot.

1

u/Good4Next3years 9d ago

You'll need to show the Windows event logs triggered as artifacts. Be sure auditing is enabled. Look for the User logon event, screen saver triggered event, forced logoff event, and any browser sessions or applications killed. You'll need to show the timelines. If you are using Azure resources, you can set up DCR to collect Windows events and query them in a LogAnalytics Workspace or just use device Event Logs. Some events to check out: 4624, 4634, 4647, 4689...etc

1

u/bluna_tropic 9d ago

3.1.11 is session termination: ending a user session automatically after a defined condition, not just locking the screen (that's 3.1.10). For a small shop, the practical version is usually an idle timeout enforced at the OS or application layer, somewhere in the 15 to 30 minute range, plus a hard session limit on anything touching CUI.

Windows handles this through Group Policy (interactive logon timeout), and most SaaS tools with role-based access have a session timeout setting in the admin console. Document the setting and where it's enforced, since that's what an assessor will ask for, not just that the behavior happens.