Enterprise Voice, Video, and Messaging Session Management Security Requirements Guide
Pick two releases to diff their requirements.
Open a previous version of this STIG.
Digest of Updates −1
Comparison against the immediately-prior release (V1R1). Rule matching uses the Group Vuln ID. Content-change detection compares the rule’s description, check, and fix text after stripping inline markup — cosmetic-only edits aren’t flagged.
Removed rules 1
- V-260023 Medium The Enterprise Voice, Video, and Messaging Session Manager must be configured to provide centralized management of session (call) records.
- RMF Control
- AC-2
- Severity
- M
- CCI
- CCI-000017
- Version
- SRG-NET-000004-VVSM-00101
- Vuln IDs
-
- V-259987
- Rule IDs
-
- SV-259987r956074_rule
Checks: C-63718r948926_chk
Verify the Enterprise Voice, Video, and Messaging Session Manager automatically disables Voice Video Endpoint user access after a 35-day period of account inactivity. This requirement refers to users rather than endpoints. If the Enterprise Voice, Video, and Messaging Session Manager does not automatically disable Voice Video Endpoint user access after a 35-day period of account inactivity, this is a finding.
Fix: F-63625r956074_fix
Configure the Enterprise Voice, Video, and Messaging Session Manager to automatically disable Voice Video Endpoint user access after a 35-day period of account inactivity.
- RMF Control
- AC-3
- Severity
- H
- CCI
- CCI-000213
- Version
- SRG-NET-000015-VVSM-00101
- Vuln IDs
-
- V-259988
- Rule IDs
-
- SV-259988r1117235_rule
Checks: C-63719r948929_chk
Verify the Enterprise Voice, Video, and Messaging Session Manager prevents auto-registration of Voice Video Endpoints. If the Enterprise Voice, Video, and Messaging Session Manager does not disable auto-registration of Voice Video Endpoints outside of these conditions, this is a finding.
Fix: F-63626r948930_fix
Configure the Enterprise Voice, Video, and Messaging Session Manager to disable auto-registration of Voice Video Endpoints.
- RMF Control
- AC-4
- Severity
- M
- CCI
- CCI-001368
- Version
- SRG-NET-000018-VVSM-00101
- Vuln IDs
-
- V-259989
- Rule IDs
-
- SV-259989r1117236_rule
Checks: C-63720r946996_chk
Verify the configuration for the extension mobility feature is only available when enabled per user. Confirm the following specific security features are configured: - The feature is enabled/disabled on a per user basis. - Feature activation requires user authentication minimally using a user unique PIN (preferably including a unique user ID). - Feature is not activated using a common activation code, or feature button on the phone. - The user (or system administrator) can manually disable the feature at their discretion. - The user may have the capability to set duration when activating the feature. (Optional) - The feature automatically deactivates based on a period of inactivity or the time of day. If the extension mobility feature is enabled and does not meet the above specific security features, this is a finding.
Fix: F-63627r946997_fix
Configure the extension mobility feature only when enabled per user. Confirm the following specific security features are configured: - The feature is enabled/disabled on a per user basis. - Feature activation requires user authentication minimally using a user unique PIN (preferably including a unique user ID). - Feature is not activated using a common activation code, or feature button on the phone. - The user (or system administrator) can manually disable the feature at their discretion. - The user may have the capability to set duration when activating the feature. (Optional) - The feature automatically deactivates based on a period of inactivity or the time of day.
- RMF Control
- AC-4
- Severity
- M
- CCI
- CCI-001368
- Version
- SRG-NET-000018-VVSM-00102
- Vuln IDs
-
- V-259990
- Rule IDs
-
- SV-259990r1117236_rule
Checks: C-63721r946999_chk
Verify the configuration for the extension mobility feature is globally disabled. If the extension mobility feature is not globally disabled, this is a finding.
Fix: F-63628r947000_fix
Configure the extension mobility feature to be globally disabled on the VVoIP system.
- RMF Control
- AC-4
- Severity
- M
- CCI
- CCI-001368
- Version
- SRG-NET-000018-VVSM-00103
- Vuln IDs
-
- V-259991
- Rule IDs
-
- SV-259991r1117236_rule
Checks: C-63722r947002_chk
Examine the configurations of the DNS server(s) serving the VVoIP system and those outside the system. Attempt to use a system specific URL that should not be published outside the system to see if an IP address is returned. This is a finding in the event restricted URLs are reachable from outside the restriction zone.
Fix: F-63629r947003_fix
Consider not using DNS for the VVoIP system unless it is required. In the event DNS is used in the VVoIP system, ensure the DNS server serving the VVoIP system is dedicated to the VVoIP system and that any DNS server interaction with other DNS servers is limited. Additionally ensure internal system URLs and information is not published to the enterprise WAN or the internet. NOTE: In the event a DNS server is implemented within the VVoIP system, the DNS STIG must be applied to the server.
- RMF Control
- AC-8
- Severity
- M
- CCI
- CCI-000048
- Version
- SRG-NET-000041-VVSM-00101
- Vuln IDs
-
- V-259992
- Rule IDs
-
- SV-259992r1173942_rule
Checks: C-63723r948935_chk
Verify the Enterprise Voice, Video, and Messaging Session Manager displays the Standard Mandatory DOD Notice and Consent Banner before granting access to management sessions. If the Enterprise Voice, Video, and Messaging Session Manager does not display the Standard Mandatory DOD Notice and Consent Banner before granting access to management sessions, this is a finding.
Fix: F-63630r948936_fix
Configure the Enterprise Voice, Video, and Messaging Session Manager to display the Standard Mandatory DOD Notice and Consent Banner before granting access to management sessions.
- RMF Control
- AC-8
- Severity
- M
- CCI
- CCI-000050
- Version
- SRG-NET-000042-VVSM-00101
- Vuln IDs
-
- V-259993
- Rule IDs
-
- SV-259993r1173943_rule
Checks: C-63724r948938_chk
Verify the Enterprise Voice, Video, and Messaging Session Manager retains the Standard Mandatory DOD Notice and Consent Banner for management sessions until the admins acknowledge the conditions. If the Enterprise Voice, Video, and Messaging Session Manager does not retain the Standard Mandatory DOD Notice and Consent Banner until the admins acknowledge the conditions, this is a finding.
Fix: F-63631r948939_fix
Configure the Enterprise Voice, Video, and Messaging Session Manager to retain the Standard Mandatory DOD Notice and Consent Banner for management sessions until the admins acknowledge the conditions.
- RMF Control
- AC-10
- Severity
- M
- CCI
- CCI-000054
- Version
- SRG-NET-000053-VVSM-00101
- Vuln IDs
-
- V-259994
- Rule IDs
-
- SV-259994r948943_rule
Checks: C-63725r948941_chk
Verify the Enterprise Voice, Video, and Messaging Session Manager limits the number of concurrent management sessions. If the Enterprise Voice, Video, and Messaging Session Manager does not limit the number of concurrent management sessions, this is a finding.
Fix: F-63632r948942_fix
Configure the Enterprise Voice, Video, and Messaging Session Manager to limit the number of concurrent management sessions.
- RMF Control
- AC-17
- Severity
- H
- CCI
- CCI-000068
- Version
- SRG-NET-000062-VVSM-00010
- Vuln IDs
-
- V-259995
- Rule IDs
-
- SV-259995r948946_rule
Checks: C-63726r948944_chk
Verify the Enterprise Voice, Video, and Messaging Session Manager uses TLS 1.2 or greater to protect the confidentiality of remote access. If the Enterprise Voice, Video, and Messaging Session Manager does not use TLS 1.2 or greater, this is a finding.
Fix: F-63633r948945_fix
Configure the Enterprise Voice, Video, and Messaging Session Manager to use TLS 1.2 or greater to protect the confidentiality of remote access.
- RMF Control
- AU-3
- Severity
- M
- CCI
- CCI-000130
- Version
- SRG-NET-000074-VVSM-00101
- Vuln IDs
-
- V-259996
- Rule IDs
-
- SV-259996r948949_rule
Checks: C-63727r948947_chk
Verify the Enterprise Voice, Video, and Messaging Session Manager produces session records containing the type of session connection. If the Enterprise Voice, Video, and Messaging Session Manager does not produce session records containing the type of session connection, this is a finding.
Fix: F-63634r948948_fix
Configure the Enterprise Voice, Video, and Messaging Session Manager to produce session records containing the type of session connection.
- RMF Control
- AU-3
- Severity
- M
- CCI
- CCI-000131
- Version
- SRG-NET-000075-VVSM-00101
- Vuln IDs
-
- V-259997
- Rule IDs
-
- SV-259997r948952_rule
Checks: C-63728r948950_chk
Verify the Enterprise Voice, Video, and Messaging Session Manager produces session records containing when (date and time) the connection was established and terminated. If the Enterprise Voice, Video, and Messaging Session Manager does not produce session records containing timestamps (date and time) for all session connections, this is a finding.
Fix: F-63635r948951_fix
Configure the Enterprise Voice, Video, and Messaging Session Manager to produce session records containing when (date and time) the connection was established and terminated.
- RMF Control
- AU-3
- Severity
- M
- CCI
- CCI-000132
- Version
- SRG-NET-000076-VVSM-00101
- Vuln IDs
-
- V-259998
- Rule IDs
-
- SV-259998r948955_rule
Checks: C-63729r948953_chk
Verify the Enterprise Voice, Video, and Messaging Session Manager produces session records containing where (location) the connection originated. If the Enterprise Voice, Video, and Messaging Session Manager does not produce session records containing where (location) the connection originated, this is a finding.
Fix: F-63636r948954_fix
Configure the Enterprise Voice, Video, and Messaging Session Manager to produce session records containing where (location) the connection originated.
- RMF Control
- AU-3
- Severity
- M
- CCI
- CCI-000133
- Version
- SRG-NET-000077-VVSM-00101
- Vuln IDs
-
- V-259999
- Rule IDs
-
- SV-259999r948958_rule
Checks: C-63730r948956_chk
Verify the Enterprise Voice, Video, and Messaging Session Manager produces session records containing the identity of the initiator of the call. The identity of the initiator of the call in this context would be the device ID or the address of the MAC or IP. For Enterprise Voice, Video, and Messaging Session Managers that have the concept of a user rather than device, this requirement is not applicable. If the Enterprise Voice, Video, and Messaging Session Manager does not produce session records containing the identity of the initiator of the call, this is a finding.
Fix: F-63637r948957_fix
Configure the Enterprise Voice, Video, and Messaging Session Manager to produce session records containing the identity of the initiator of the call.
- RMF Control
- AU-3
- Severity
- M
- CCI
- CCI-000134
- Version
- SRG-NET-000078-VVSM-00101
- Vuln IDs
-
- V-260000
- Rule IDs
-
- SV-260000r948961_rule
Checks: C-63731r948959_chk
Verify the Enterprise Voice, Video, and Messaging Session Manager produces session records containing the outcome (status) of the connection. The outcome or status of a call includes call completed normally, busy endpoint, busy network, preempted, or other pertinent description. If the Enterprise Voice, Video, and Messaging Session Manager does not produce session records containing the outcome (status) of the connection, this is a finding.
Fix: F-63638r948960_fix
Configure the Enterprise Voice, Video, and Messaging Session Manager to produce session records containing the outcome (status) of the connection.
- RMF Control
- AU-3
- Severity
- M
- CCI
- CCI-001487
- Version
- SRG-NET-000079-VVSM-00101
- Vuln IDs
-
- V-260001
- Rule IDs
-
- SV-260001r948964_rule
Checks: C-63732r948962_chk
Verify the Enterprise Voice, Video, and Messaging Session Manager produces session records containing the identity of the users and identifiers associated with the session. The identity of the users and identifiers of the call in this context would be the user ID or user name. For Enterprise Voice, Video, and Messaging Session Managers that have the concept of a device rather than users and identifiers, this requirement is not applicable. If the Enterprise Voice, Video, and Messaging Session Manager does not produce session records containing the identity of the users and identifiers associated with the session, this is a finding.
Fix: F-63639r948963_fix
Configure the Enterprise Voice, Video, and Messaging Session Manager to produce session records containing the identity of the users and identifiers associated with the session.
- RMF Control
- AU-5
- Severity
- M
- CCI
- CCI-000139
- Version
- SRG-NET-000088-VVSM-00101
- Vuln IDs
-
- V-260002
- Rule IDs
-
- SV-260002r948967_rule
Checks: C-63733r948965_chk
Verify the Enterprise Voice, Video, and Messaging Session Manager alerts the ISSO and SA (at a minimum) in the event of a session record system failure. If the Enterprise Voice, Video, and Messaging Session Manager does not alert the ISSO and SA (at a minimum) in the event of a session record system failure, this is a finding.
Fix: F-63640r948966_fix
Configure the Enterprise Voice, Video, and Messaging Session Manager to alert the ISSO and SA (at a minimum) in the event of a session record system failure.
- RMF Control
- AU-9
- Severity
- M
- CCI
- CCI-000162
- Version
- SRG-NET-000098-VVSM-00101
- Vuln IDs
-
- V-260003
- Rule IDs
-
- SV-260003r948970_rule
Checks: C-63734r948968_chk
Verify the Enterprise Voice, Video, and Messaging Session Manager protects session records from unauthorized read access. If the Enterprise Voice, Video, and Messaging Session Manager does not protect session records from unauthorized read access, this is a finding.
Fix: F-63641r948969_fix
Configure the Enterprise Voice, Video, and Messaging Session Manager to protect session records from unauthorized read access.
- RMF Control
- AU-9
- Severity
- M
- CCI
- CCI-000163
- Version
- SRG-NET-000099-VVSM-00101
- Vuln IDs
-
- V-260004
- Rule IDs
-
- SV-260004r948973_rule
Checks: C-63735r948971_chk
Verify the Enterprise Voice, Video, and Messaging Session Manager protects session records from unauthorized modification. If the Enterprise Voice, Video, and Messaging Session Manager does not protect session records from unauthorized modification, this is a finding.
Fix: F-63642r948972_fix
Configure the Enterprise Voice, Video, and Messaging Session Manager to protect session records from unauthorized modification.
- RMF Control
- AU-9
- Severity
- M
- CCI
- CCI-000164
- Version
- SRG-NET-000100-VVSM-00101
- Vuln IDs
-
- V-260005
- Rule IDs
-
- SV-260005r948976_rule
Checks: C-63736r948974_chk
Verify the Enterprise Voice, Video, and Messaging Session Manager protects session records from unauthorized deletion. If the Enterprise Voice, Video, and Messaging Session Manager does not protect session records from unauthorized deletion, this is a finding.
Fix: F-63643r948975_fix
Configure the Enterprise Voice, Video, and Messaging Session Manager to protect session records from unauthorized deletion.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000169
- Version
- SRG-NET-000113-VVSM-00101
- Vuln IDs
-
- V-260006
- Rule IDs
-
- SV-260006r948979_rule
Checks: C-63737r948977_chk
Verify the Enterprise Voice, Video, and Messaging Session Manager produces session records for events determined to be significant and relevant by local policy. If the Enterprise Voice, Video, and Messaging Session Manager does not produce session records for events determined to be significant and relevant by local policy, this is a finding.
Fix: F-63644r948978_fix
Configure the Enterprise Voice, Video, and Messaging Session Manager to produce session records for events determined to be significant and relevant by local policy.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- SRG-NET-000131-VVSM-00101
- Vuln IDs
-
- V-260007
- Rule IDs
-
- SV-260007r948982_rule
Checks: C-63738r948980_chk
Verify the Enterprise Voice, Video, and Messaging Session Manager is configured to disable nonessential capabilities. If the Enterprise Voice, Video, and Messaging Session Manager is not configured to disable nonessential capabilities, this is a finding.
Fix: F-63645r948981_fix
Configure the Enterprise Voice, Video, and Messaging Session Manager to be configured to disable nonessential capabilities.
- RMF Control
- CM-7
- Severity
- H
- CCI
- CCI-000382
- Version
- SRG-NET-000132-VVSM-00101
- Vuln IDs
-
- V-260008
- Rule IDs
-
- SV-260008r948985_rule
Checks: C-63739r948983_chk
Verify the Enterprise Voice, Video, and Messaging Session Manager only uses ports, protocols, and services allowed per the PPSM CAL and VAs. If the Enterprise Voice, Video, and Messaging Session Manager uses ports, protocols, and services other than those permitted by the PPSM CAL and VAs, this is a finding.
Fix: F-63646r948984_fix
Configure the Enterprise Voice, Video, and Messaging Session Manager to only use of ports, protocols, and services allowed per the PPSM CAL and VAs.
- RMF Control
- IA-2
- Severity
- H
- CCI
- CCI-000764
- Version
- SRG-NET-000138-VVSM-00101
- Vuln IDs
-
- V-260009
- Rule IDs
-
- SV-260009r948988_rule
Checks: C-63740r948986_chk
Verify the Enterprise Voice, Video, and Messaging Session Manager uniquely identifies all users. If the Enterprise Voice, Video, and Messaging Session Manager does not uniquely identify all users, then is a finding.
Fix: F-63647r948987_fix
Configure the Enterprise Voice, Video, and Messaging Session Manager to uniquely identify all users.
- RMF Control
- IA-2
- Severity
- H
- CCI
- CCI-000764
- Version
- SRG-NET-000138-VVSM-00102
- Vuln IDs
-
- V-260010
- Rule IDs
-
- SV-260010r948991_rule
Checks: C-63741r948989_chk
Verify the Enterprise Voice, Video, and Messaging Session Manager is configured to use an organizational level user account management system. If the Enterprise Voice, Video, and Messaging Session Manager is not configured to use an organizational level user account management system, then is a finding.
Fix: F-63648r948990_fix
Configure the Enterprise Voice, Video, and Messaging Session Manager to use an organizational level user account management system.
- RMF Control
- IA-2
- Severity
- M
- CCI
- CCI-001941
- Version
- SRG-NET-000147-VVSM-00101
- Vuln IDs
-
- V-260011
- Rule IDs
-
- SV-260011r1173877_rule
Checks: C-63742r948992_chk
Verify the Enterprise Voice, Video, and Messaging Session Manager implements attack-resistant mechanisms for Voice Video Endpoint registration. If the Enterprise Voice, Video, and Messaging Session Manager does not implement attack-resistant mechanisms for Voice Video Endpoint registration, this is a finding.
Fix: F-63649r948993_fix
Configure the Enterprise Voice, Video, and Messaging Session Manager to implement attack-resistant mechanisms for Voice Video Endpoint registration.
- RMF Control
- IA-3
- Severity
- M
- CCI
- CCI-000778
- Version
- SRG-NET-000148-VVSM-00101
- Vuln IDs
-
- V-260012
- Rule IDs
-
- SV-260012r948997_rule
Checks: C-63743r948995_chk
Verify the Enterprise Voice, Video, and Messaging Session Manager uniquely identifies all Voice Video Endpoint devices before registration. If the Enterprise Voice, Video, and Messaging Session Manager does not uniquely identify all Voice Video Endpoint devices before registration, this is a finding.
Fix: F-63650r948996_fix
Configure the Enterprise Voice, Video, and Messaging Session Manager to uniquely identify all Voice Video Endpoint devices before registering those devices.
- RMF Control
- SC-10
- Severity
- M
- CCI
- CCI-001133
- Version
- SRG-NET-000213-VVSM-00101
- Vuln IDs
-
- V-260013
- Rule IDs
-
- SV-260013r971530_rule
Checks: C-63744r948998_chk
Verify the Enterprise Voice, Video, and Messaging Session Manager terminates all network connections associated with a communications session at the end of the session. If the Enterprise Voice, Video, and Messaging Session Manager does not terminate all network connections associated with a communications session at the end of the session, this is a finding.
Fix: F-63651r948999_fix
Configure the Enterprise Voice, Video, and Messaging Session Manager to terminate all network connections associated with a communications session at the end of the session.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SRG-NET-000225-VVSM-00101
- Vuln IDs
-
- V-260014
- Rule IDs
-
- SV-260014r949003_rule
Checks: C-63745r949001_chk
Verify the Enterprise Voice, Video, and Messaging Session Manager supporting C2 communications associates MLPP attributes when exchanged between UC systems. If the Enterprise Voice, Video, and Messaging Session Manager supporting C2 communications does not associate MLPP attributes when exchanged between UC systems, this is a finding.
Fix: F-63652r949002_fix
Configure the Enterprise Voice, Video, and Messaging Session Manager supporting C2 communications to associate MLPP attributes when exchanged between UC systems.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SRG-NET-000226-VVSM-00101
- Vuln IDs
-
- V-260015
- Rule IDs
-
- SV-260015r1117232_rule
Checks: C-63746r949004_chk
Verify the Enterprise Voice, Video, and Messaging Session Manager supporting C2 communications validates the integrity of transmitted MLPP attributes. If the Enterprise Voice, Video, and Messaging Session Manager supporting C2 communications does not validate the integrity of transmitted MLPP attributes, this is a finding.
Fix: F-63653r949005_fix
Configure the Enterprise Voice, Video, and Messaging Session Manager supporting C2 communications to validate the integrity of transmitted MLPP attributes.
- RMF Control
- SC-23
- Severity
- H
- CCI
- CCI-001184
- Version
- SRG-NET-000230-VVSM-00101
- Vuln IDs
-
- V-260016
- Rule IDs
-
- SV-260016r949009_rule
Checks: C-63747r949007_chk
Verify the Enterprise Voice, Video, and Messaging Session Manager is configured to use FIPS-validated SHA-2 or higher to protect the authenticity of communications sessions. Note: The use of SHA-1 in accordance with SP800-131Ar2 will also meet this requirement. If the Enterprise Voice, Video, and Messaging Session Manager is not configured to use FIPS-validated SHA-2 or higher, this is a finding.
Fix: F-63654r949008_fix
Configure the Enterprise Voice, Video, and Messaging Session Manager to use FIPS-validated SHA-2 or higher to protect communications sessions.
- RMF Control
- SC-24
- Severity
- M
- CCI
- CCI-001190
- Version
- SRG-NET-000235-VVSM-00101
- Vuln IDs
-
- V-260017
- Rule IDs
-
- SV-260017r949012_rule
Checks: C-63748r949010_chk
Verify the Enterprise Voice, Video, and Messaging Session Manager fails to a secure state when system initialization fails, shutdown fails, or aborts fail. If the Enterprise Voice, Video, and Messaging Session Manager does not fail to a secure state if system initialization fails, shutdown fails, or aborts fail, this is a finding.
Fix: F-63655r949011_fix
Configure the Enterprise Voice, Video, and Messaging Session Manager to fail to a secure state if system initialization fails, shutdown fails, or aborts fail.
- RMF Control
- SC-24
- Severity
- M
- CCI
- CCI-001665
- Version
- SRG-NET-000236-VVSM-00101
- Vuln IDs
-
- V-260018
- Rule IDs
-
- SV-260018r949015_rule
Checks: C-63749r949013_chk
Verify that in the event of a system failure, the Enterprise Voice, Video, and Messaging Session Managers preserves any information necessary to determine cause of failure and any information necessary to return to operations with least disruption to mission processes. If the Enterprise Voice, Video, and Messaging Session Managers does not preserve all information necessary to determine cause of failure, this is a finding. If the Enterprise Voice, Video, and Messaging Session Managers does not preserve all information necessary to return to operations with least disruption to mission processes, this is a finding.
Fix: F-63656r949014_fix
Configure the Enterprise Voice, Video, and Messaging Session Manager, in the event of a system failure, to preserve any information necessary to determine cause of failure and any information necessary to return to operations with least disruption to mission processes.
- RMF Control
- SI-11
- Severity
- M
- CCI
- CCI-001312
- Version
- SRG-NET-000273-VVSM-00101
- Vuln IDs
-
- V-260019
- Rule IDs
-
- SV-260019r949018_rule
Checks: C-63750r949016_chk
Verify the Enterprise Voice, Video, and Messaging Session Manager generates session records that provide information necessary for corrective actions without revealing personally identifiable information or sensitive information. If the Enterprise Voice, Video, and Messaging Session Manager does not generate session records that provide information necessary for corrective actions without revealing personally identifiable information or sensitive information, this is a finding.
Fix: F-63657r949017_fix
Configure the Enterprise Voice, Video, and Messaging Session Manager to generate session records that provide information necessary for corrective actions without revealing personally identifiable information or sensitive information.
- RMF Control
- AC-2
- Severity
- M
- CCI
- CCI-002145
- Version
- SRG-NET-000315-VVSM-00101
- Vuln IDs
-
- V-260020
- Rule IDs
-
- SV-260020r949021_rule
Checks: C-63751r949019_chk
Verify the Enterprise Voice, Video, and Messaging Session Manager provides the capability to restrict Enterprise Voice, Video, and Messaging Session Manager access outside of operational hours to allow only essential connection capability. Areas requiring extended service times may be identified as exceptions. If the Enterprise Voice, Video, and Messaging Session Manager does not restrict Enterprise Voice, Video, and Messaging Session Manager access outside of operational hours allowing for exceptions, this is a finding.
Fix: F-63658r949020_fix
Configure the Enterprise Voice, Video, and Messaging Session Manager to restrict Enterprise Voice, Video, and Messaging Session Manager access outside of operational hours to only essential connections.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SRG-NET-000321-VVSM-00101
- Vuln IDs
-
- V-260021
- Rule IDs
-
- SV-260021r987749_rule
Checks: C-63752r949022_chk
Verify the Enterprise Voice, Video, and Messaging Session Manager enforces change to privileges of Voice Video Endpoint user access. Privileges include access to outside connections, precedence, and preemption capabilities. If the Enterprise Voice, Video, and Messaging Session Manager does not enforce changes to privileges of Voice Video Endpoint user access, this is a finding.
Fix: F-63659r949023_fix
Configure the Enterprise Voice, Video, and Messaging Session Manager to enforce changes to privileges of Voice Video Endpoint user access.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SRG-NET-000322-VVSM-00101
- Vuln IDs
-
- V-260022
- Rule IDs
-
- SV-260022r987750_rule
Checks: C-63753r949025_chk
Verify the Enterprise Voice, Video, and Messaging Session Manager enforces change to privileges of Voice Video Endpoint device access. Privileges include access to outside connections, precedence, and preemption capabilities. If the Enterprise Voice, Video, and Messaging Session Manager does not enforce changes to privileges of Voice Video Endpoint device access, this is a finding.
Fix: F-63660r949026_fix
Configure the Enterprise Voice, Video, and Messaging Session Manager to enforce changes to privileges of Voice Video Endpoint device access.
- RMF Control
- AU-4
- Severity
- H
- CCI
- CCI-001851
- Version
- SRG-NET-000334-VVSM-00101
- Vuln IDs
-
- V-260024
- Rule IDs
-
- SV-260024r949033_rule
Checks: C-63755r949031_chk
Verify the Enterprise Voice, Video, and Messaging Session Manager offloads session records to a central log server. If the Enterprise Voice, Video, and Messaging Session Manager does not offload session records to a central log server, this is a finding.
Fix: F-63662r949032_fix
Configure the Enterprise Voice, Video, and Messaging Session Manager to offload session records to a central log server.
- RMF Control
- IA-11
- Severity
- M
- CCI
- CCI-002038
- Version
- SRG-NET-000338-VVSM-00101
- Vuln IDs
-
- V-260025
- Rule IDs
-
- SV-260025r1173880_rule
Checks: C-63756r949034_chk
Verify the Enterprise Voice, Video, and Messaging Session Manager requires Voice Video Endpoints to re-register at least every three hours. If the Enterprise Voice, Video, and Messaging Session Manager does not require Voice Video Endpoints to re-register or does not enforce re-registration at least every three hours, this is a finding.
Fix: F-63663r949035_fix
Configure the Enterprise Voice, Video, and Messaging Session Manager to re-register Voice Video Endpoints at least every three hours.
- RMF Control
- IA-11
- Severity
- M
- CCI
- CCI-002038
- Version
- SRG-NET-000338-VVSM-00102
- Vuln IDs
-
- V-260026
- Rule IDs
-
- SV-260026r1173881_rule
Checks: C-63757r949037_chk
Verify the Enterprise Voice, Video, and Messaging Session Manager requires Voice Video peers to re-register (reauthenticate) at least every hour. If the Enterprise Voice, Video, and Messaging Session Manager does not require Voice Video peers to re-register (reauthenticate) at least every hour, this is a finding.
Fix: F-63664r949038_fix
Configure the Enterprise Voice, Video, and Messaging Session Manager to re-register (reauthenticate) Voice Video peers at least every hour.
- RMF Control
- IA-3
- Severity
- M
- CCI
- CCI-001958
- Version
- SRG-NET-000343-VVSM-00101
- Vuln IDs
-
- V-260027
- Rule IDs
-
- SV-260027r949042_rule
Checks: C-63758r949040_chk
Verify the Enterprise Voice, Video, and Messaging Session Manager authenticates all Voice Video Endpoint devices before establishing any connection. If the Enterprise Voice, Video, and Messaging Session Manager does not authenticate all Voice Video Endpoint devices before establishing any connection, this is a finding.
Fix: F-63665r949041_fix
Configure the Enterprise Voice, Video, and Messaging Session Manager to authenticate all Voice Video Endpoint devices before registering those devices.
- RMF Control
- IA-3
- Severity
- M
- CCI
- CCI-001958
- Version
- SRG-NET-000343-VVSM-00102
- Vuln IDs
-
- V-260028
- Rule IDs
-
- SV-260028r949045_rule
Checks: C-63759r949043_chk
Verify the Enterprise Voice, Video, and Messaging Session Manager authenticates all Voice Video peers (trunks) before establishing any connection. If the Enterprise Voice, Video, and Messaging Session Manager does not authenticate all Voice Video peers (trunks) before establishing any connection, this is a finding.
Fix: F-63666r949044_fix
Configure the Enterprise Voice, Video, and Messaging Session Manager to authenticate all Voice Video peers (trunks) before registration.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SRG-NET-000353-VVSM-00101
- Vuln IDs
-
- V-260029
- Rule IDs
-
- SV-260029r987762_rule
Checks: C-63760r949046_chk
Verify the Enterprise Voice, Video, and Messaging Session Manager provides an indication of current participants in all calls, meetings, and conferences. If the Enterprise Voice, Video, and Messaging Session Manager does not provide an indication of current participants in all calls, meetings and conferences, this is a finding.
Fix: F-63667r949047_fix
Configure the Enterprise Voice, Video, and Messaging Session Manager to provide an indication of current participants in all calls, meetings, and conferences.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SRG-NET-000354-VVSM-00101
- Vuln IDs
-
- V-260030
- Rule IDs
-
- SV-260030r949051_rule
Checks: C-63761r949049_chk
Verify the Enterprise Voice, Video, and Messaging Session Manager supporting C2 communications associates MLPP attributes when exchanged between UC system components. If the Enterprise Voice, Video, and Messaging Session Manager supporting C2 communications does not associate MLPP attributes when exchanged between UC system components, this is a finding.
Fix: F-63668r949050_fix
Configure the Enterprise Voice, Video, and Messaging Session Manager supporting C2 communications to associate MLPP attributes when exchanged between UC system components.
- RMF Control
- SC-23
- Severity
- M
- CCI
- CCI-002470
- Version
- SRG-NET-000355-VVSM-00010
- Vuln IDs
-
- V-260031
- Rule IDs
-
- SV-260031r956076_rule
Checks: C-63762r956075_chk
Verify the Enterprise Voice, Video, and Messaging Session Manager, when using PKI, only uses DOD-approved certificate authorities. If the Enterprise Voice, Video, and Messaging Session Manager, when using PKI, does not use DOD-approved certificate authorities, this is a finding.
Fix: F-63669r956076_fix
Configure the Enterprise Voice, Video, and Messaging Session Manager to only use DOD-approved certificate authorities when using PKI.
- RMF Control
- SC-5
- Severity
- M
- CCI
- CCI-002385
- Version
- SRG-NET-000362-VVSM-00101
- Vuln IDs
-
- V-260032
- Rule IDs
-
- SV-260032r949057_rule
Checks: C-63763r949055_chk
Verify the Enterprise Voice, Video, and Messaging Session Manager is configured to protect against or limit all types of DoS attacks. If the Enterprise Voice, Video, and Messaging Session Manager is not configured to protect against or limit all types of DoS attacks, this is a finding.
Fix: F-63670r949056_fix
Configure the Enterprise Voice, Video, and Messaging Session Manager to protect against or limit all types of DoS attacks.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SRG-NET-000363-VVSM-00019
- Vuln IDs
-
- V-260033
- Rule IDs
-
- SV-260033r987769_rule
Checks: C-63764r949058_chk
Verify the Enterprise Voice, Video, and Messaging Session Manager limits and reserves bandwidth based on priority of the traffic type. If the Enterprise Voice, Video, and Messaging Session Manager does not limit and reserve bandwidth based on priority of the traffic type, this is a finding.
Fix: F-63671r949059_fix
Configure the Enterprise Voice, Video, and Messaging Session Manager to limit and reserve bandwidth based on priority of the traffic type.
- RMF Control
- SC-8
- Severity
- H
- CCI
- CCI-002418
- Version
- SRG-NET-000371-VVSM-00101
- Vuln IDs
-
- V-260034
- Rule IDs
-
- SV-260034r949063_rule
Checks: C-63765r949061_chk
Verify the Enterprise Voice, Video, and Messaging Session Manager protects the confidentiality and integrity of transmitted configuration files, signaling, and media streams. If the Enterprise Voice, Video, and Messaging Session Manager does not protect the confidentiality and integrity of transmitted configuration files, signaling, and media streams, this is a finding.
Fix: F-63672r949062_fix
Configure the Enterprise Voice, Video, and Messaging Session Manager to protect the confidentiality and integrity of transmitted configuration files, signaling, and media streams.
- RMF Control
- AC-7
- Severity
- M
- CCI
- CCI-002238
- Version
- SRG-NET-000395-VVSM-00010
- Vuln IDs
-
- V-260035
- Rule IDs
-
- SV-260035r949066_rule
Checks: C-63766r949064_chk
Verify the Enterprise Voice, Video, and Messaging Session Manager, when using locally stored user accounts, automatically locks the account until released by an administrator when three unsuccessful logon attempts in 15 minutes are exceeded. If the Enterprise Voice, Video, and Messaging Session Manager, when using locally stored user accounts, does not automatically lock the account until released by an administrator when three unsuccessful logon attempts in 15 minutes are exceeded, this is a finding.
Fix: F-63673r949065_fix
Configure the Enterprise Voice, Video, and Messaging Session Manager, when using locally stored user accounts, to automatically lock the account until released by an administrator when three unsuccessful logon attempts in 15 minutes are exceeded.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000197
- Version
- SRG-NET-000400-VVSM-00101
- Vuln IDs
-
- V-260036
- Rule IDs
-
- SV-260036r949069_rule
Checks: C-63767r949067_chk
Verify the Enterprise Voice, Video, and Messaging Session Manager, for accounts using password authentication, is configured to SHA-2 or greater to protect the integrity of the password authentication process. Note: The use of SHA-1 in accordance with SP800-131Ar2 will also meet this requirement. If the Enterprise Voice, Video, and Messaging Session Manager is not configured to use SHA-2 or greater to protect the password authentication process, this is a finding.
Fix: F-63674r949068_fix
For accounts using password authentication, configure the Enterprise Voice, Video, and Messaging Session Manager to use SHA-2 or greater to protect the integrity of the password authentication process.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- SRG-NET-000506-VVSM-00010
- Vuln IDs
-
- V-260037
- Rule IDs
-
- SV-260037r949072_rule
Checks: C-63768r949070_chk
Verify the Enterprise Voice, Video, and Messaging Session Manager is configured to generate session (call) records when concurrent logons from multiple endpoints occur. If the Enterprise Voice, Video, and Messaging Session Manager is not configured to generate session (call) records when concurrent logons from multiple endpoints occur, this is a finding.
Fix: F-63675r949071_fix
Configure the Enterprise Voice, Video, and Messaging Session Manager to generate session (call) records when concurrent logons from multiple endpoints occur.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- SRG-NET-000509-VVSM-00010
- Vuln IDs
-
- V-260038
- Rule IDs
-
- SV-260038r949075_rule
Checks: C-63769r949073_chk
Verify the Enterprise Voice, Video, and Messaging Session Manager, when using locally stored user accounts, is configured to generate audit records for all account creation, modification, disabling, and termination events. If the Enterprise Voice, Video, and Messaging Session Manager is not configured to generate audit records for all account creation, modification, disabling, and termination events, this is a finding.
Fix: F-63676r949074_fix
When using locally stored user accounts, configure the Enterprise Voice, Video, and Messaging Session Manager to generate audit records for all account creation, modification, disabling, and termination events.
- RMF Control
- SC-13
- Severity
- H
- CCI
- CCI-002450
- Version
- SRG-NET-000510-VVSM-00101
- Vuln IDs
-
- V-260039
- Rule IDs
-
- SV-260039r1117247_rule
Checks: C-63770r949076_chk
Verify the Enterprise Voice, Video, and Messaging Session Manager implements NIST FIPS-validated cryptography for communications sessions. If the Enterprise Voice, Video, and Messaging Session Manager does not implements NIST FIPS-validated cryptography for communications sessions, this is a finding.
Fix: F-63677r949077_fix
Configure the Enterprise Voice, Video, and Messaging Session Manager to implement NIST FIPS-validated cryptography for communications sessions.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SRG-NET-000512-VVSM-00101
- Vuln IDs
-
- V-260040
- Rule IDs
-
- SV-260040r949081_rule
Checks: C-63771r949079_chk
Verify the Enterprise Voice, Video, and Messaging Session Manager is configured to use the organization authoritative time source (NTP). If the Enterprise Voice, Video, and Messaging Session Manager is not configured to use the organization authoritative time source, this is a finding.
Fix: F-63678r949080_fix
Configure the Enterprise Voice, Video, and Messaging Session Manager to use the organization authoritative time source.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SRG-NET-000512-VVSM-00130
- Vuln IDs
-
- V-260041
- Rule IDs
-
- SV-260041r949084_rule
Checks: C-63772r949082_chk
Verify the Enterprise Voice, Video, and Messaging Session Manager is configured in accordance with the security configuration settings based on DOD security configuration or implementation guidance, including STIGs, NSA configuration guides, CTOs, and DTMs. If the Enterprise Voice, Video, and Messaging Session Manager is not configured in accordance with the security configuration settings based on DOD security configuration or implementation guidance, including STIGs, NSA configuration guides, CTOs, and DTMs, this is a finding.
Fix: F-63679r949083_fix
Configure the Enterprise Voice, Video, and Messaging Session Manager in accordance with the security configuration settings based on DOD security configuration or implementation guidance, including STIGs, NSA configuration guides, CTOs, and DTMs.
- RMF Control
- AC-12
- Severity
- M
- CCI
- CCI-002363
- Version
- SRG-NET-000518-VVSM-00101
- Vuln IDs
-
- V-260042
- Rule IDs
-
- SV-260042r949087_rule
Checks: C-63773r949085_chk
Verify the Enterprise Voice, Video, and Messaging Session Manager requiring user access authentication provides a logout capability for user-initiated communications sessions. If the Enterprise Voice, Video, and Messaging Session Manager requiring user access authentication does not provide a logout capability for user-initiated communications sessions, this is a finding.
Fix: F-63680r949086_fix
Configure the Enterprise Voice, Video, and Messaging Session Manager requiring user access authentication to provide a logout capability for user-initiated communications sessions.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SRG-NET-000520-VVSM-00101
- Vuln IDs
-
- V-260043
- Rule IDs
-
- SV-260043r1117223_rule
Checks: C-63774r949088_chk
Verify the Enterprise Voice, Video, and Messaging Session Manager applies 802.1Q VLAN tags to signaling and media traffic. If the Enterprise Voice, Video, and Messaging Session Manager does not apply 802.1Q VLAN tags to signaling and media traffic, this is a finding.
Fix: F-63681r949089_fix
Configure the Enterprise Voice, Video, and Messaging Session Manager to apply 802.1Q VLAN tags to signaling and media traffic or be in a private subnet.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SRG-NET-000520-VVSM-00102
- Vuln IDs
-
- V-260044
- Rule IDs
-
- SV-260044r1117223_rule
Checks: C-63775r949091_chk
Verify the Enterprise Voice, Video, and Messaging Session Manager uses a voice or video VLAN separate from all other VLANs. If the Enterprise Voice, Video, and Messaging Session Manager uses a voice or video VLAN that is not separate from all other VLANs, this is a finding.
Fix: F-63682r949092_fix
Configure the Enterprise Voice, Video, and Messaging Session Manager to use a voice or video VLAN, separate from all other VLANs.
- RMF Control
- Severity
- M
- CCI
- CCI-004062
- Version
- SRG-NET-000522-VVSM-00010
- Vuln IDs
-
- V-260045
- Rule IDs
-
- SV-260045r1173878_rule
Checks: C-63776r949094_chk
Verify the Enterprise Voice, Video, and Messaging Session Manager, when using locally stored user accounts, is configured to only store cryptographic representations of passwords. If the Enterprise Voice, Video, and Messaging Session Manager is not configured to only store cryptographic representations of passwords, this is a finding.
Fix: F-63683r949095_fix
Configure the Enterprise Voice, Video, and Messaging Session Manager, when using locally stored user accounts, to only store cryptographic representations of passwords.
- RMF Control
- AC-17
- Severity
- H
- CCI
- CCI-001453
- Version
- SRG-NET-000530-VVSM-00010
- Vuln IDs
-
- V-260046
- Rule IDs
-
- SV-260046r949099_rule
Checks: C-63777r949097_chk
Verify the Enterprise Voice, Video, and Messaging Session Manager is configured to only use TLS 1.2 or greater for all TLS and SSL communications. If the Voice Video Session is not configured to only use TLS 1.2 or greater for all TLS and SSL communications, this is a finding.
Fix: F-63684r949098_fix
Configure the Enterprise Voice, Video, and Messaging Session Manager to only use TLS 1.2 or greater for all TLS and SSL communications.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000185
- Version
- SRG-NET-000580-VVSM-00010
- Vuln IDs
-
- V-260047
- Rule IDs
-
- SV-260047r949102_rule
Checks: C-63778r949100_chk
Verify the Enterprise Voice, Video, and Messaging Session Manager, when using PKI, is configured to validate certificates using RFC 5280 path validation. If the Enterprise Voice, Video, and Messaging Session Manager is not configured to validate certificates using RFC 5280 path validation, this is a finding.
Fix: F-63685r949101_fix
Configure the Enterprise Voice, Video, and Messaging Session Manager, when using PKI, to validate certificates using RFC 5280 path validation.