This objective requires organizations to define and document the specific conditions under which a user session must be terminated. It focuses on understanding when and why systems should end a session entirely—not just lock it—especially when dealing with Controlled Unclassified Information (CUI).