<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://cmmcwiki.org/index.php?action=history&amp;feed=atom&amp;title=LLMResponse_MA.L2-3.7.5.b</id>
	<title>LLMResponse MA.L2-3.7.5.b - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://cmmcwiki.org/index.php?action=history&amp;feed=atom&amp;title=LLMResponse_MA.L2-3.7.5.b"/>
	<link rel="alternate" type="text/html" href="https://cmmcwiki.org/index.php?title=LLMResponse_MA.L2-3.7.5.b&amp;action=history"/>
	<updated>2026-06-21T07:17:18Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.43.8</generator>
	<entry>
		<id>https://cmmcwiki.org/index.php?title=LLMResponse_MA.L2-3.7.5.b&amp;diff=1388&amp;oldid=prev</id>
		<title>David: Created page with &quot;For assessment objective [b], which focuses on ensuring nonlocal maintenance sessions are terminated when maintenance is complete, I&#039;ll provide rankings and prioritization based on the CMMC requirements.  == Ranking of Evidence Types ==  For the termination of nonlocal maintenance sessions, I recommend ranking evidence types as follows:  1. **Screen Share (I4)** - Highest value evidence as it allows direct observation of the session termination process, showing both manu...&quot;</title>
		<link rel="alternate" type="text/html" href="https://cmmcwiki.org/index.php?title=LLMResponse_MA.L2-3.7.5.b&amp;diff=1388&amp;oldid=prev"/>
		<updated>2025-04-02T04:44:08Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;For assessment objective [b], which focuses on ensuring nonlocal maintenance sessions are terminated when maintenance is complete, I&amp;#039;ll provide rankings and prioritization based on the CMMC requirements.  == Ranking of Evidence Types ==  For the termination of nonlocal maintenance sessions, I recommend ranking evidence types as follows:  1. **Screen Share (I4)** - Highest value evidence as it allows direct observation of the session termination process, showing both manu...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;For assessment objective [b], which focuses on ensuring nonlocal maintenance sessions are terminated when maintenance is complete, I&amp;#039;ll provide rankings and prioritization based on the CMMC requirements.&lt;br /&gt;
&lt;br /&gt;
== Ranking of Evidence Types ==&lt;br /&gt;
&lt;br /&gt;
For the termination of nonlocal maintenance sessions, I recommend ranking evidence types as follows:&lt;br /&gt;
&lt;br /&gt;
1. **Screen Share (I4)** - Highest value evidence as it allows direct observation of the session termination process, showing both manual logoff procedures and any automatic termination mechanisms in action.&lt;br /&gt;
&lt;br /&gt;
2. **Artifacts (I1)** - Very valuable evidence including system logs showing session establishment and termination timestamps, audit records of session activities, and connection state records.&lt;br /&gt;
&lt;br /&gt;
3. **Physical Review (I3)** - Allows on-premise observation of configuration settings for session termination policies and timeout parameters.&lt;br /&gt;
&lt;br /&gt;
4. **Documents (I2)** - Provides foundational evidence through policies and procedures for session termination, but needs to be supported by the other evidence types to demonstrate actual implementation.&lt;br /&gt;
&lt;br /&gt;
== Prioritization of Assessment Approaches ==&lt;br /&gt;
&lt;br /&gt;
For obtaining evidence related to session termination, I recommend prioritizing approaches as:&lt;br /&gt;
&lt;br /&gt;
1. **Test (C3)** - Primary approach that provides direct evidence of functionality by:&lt;br /&gt;
   - Observing actual termination of nonlocal maintenance sessions&lt;br /&gt;
   - Verifying both manual termination procedures and automatic timeout mechanisms&lt;br /&gt;
   - Confirming network connections are fully closed after maintenance activities&lt;br /&gt;
&lt;br /&gt;
2. **Examine (C1)** - Important supporting approach focusing on:&lt;br /&gt;
   - System configuration settings for session timeouts&lt;br /&gt;
   - Session logs showing start and end timestamps&lt;br /&gt;
   - Documentation of termination policies specific to maintenance sessions&lt;br /&gt;
&lt;br /&gt;
3. **Interview (C2)** - Provides contextual understanding through:&lt;br /&gt;
   - Discussions with administrators about termination procedures&lt;br /&gt;
   - Verification that maintenance personnel understand termination requirements&lt;br /&gt;
   - Clarification of any automatic versus manual termination processes&lt;br /&gt;
&lt;br /&gt;
== Key Assessment Objects ==&lt;br /&gt;
&lt;br /&gt;
For these approaches, these specific assessment objects would be most valuable:&lt;br /&gt;
&lt;br /&gt;
**Test:**&lt;br /&gt;
- Mechanisms for terminating nonlocal maintenance sessions&lt;br /&gt;
- Network connection states before and after session termination&lt;br /&gt;
- Verification that terminated sessions cannot be resumed without re-authentication&lt;br /&gt;
&lt;br /&gt;
**Examine:**&lt;br /&gt;
- System configuration settings for session timeouts&lt;br /&gt;
- Maintenance logs showing session termination timestamps&lt;br /&gt;
- Security procedures documenting proper session termination&lt;br /&gt;
&lt;br /&gt;
**Interview:**&lt;br /&gt;
- System administrators responsible for maintenance session configuration&lt;br /&gt;
- Maintenance personnel who regularly perform nonlocal maintenance&lt;br /&gt;
- Security personnel who monitor remote access&lt;br /&gt;
&lt;br /&gt;
This comprehensive approach will provide strong evidence that nonlocal maintenance sessions are properly terminated when maintenance is complete, satisfying the requirement in MA.L2-3.7.5 [b].&lt;/div&gt;</summary>
		<author><name>David</name></author>
	</entry>
</feed>