Microsoft Skype for Business 2016 Security Technical Implementation Guide
Pick two releases to diff their requirements.
Open a previous version of this STIG.
Digest of Updates +4 −3
Comparison against the immediately-prior release (V1R1). Rule matching uses the Group Vuln ID. Content-change detection compares the rule’s description, check, and fix text after stripping inline markup — cosmetic-only edits aren’t flagged.
Added rules 4
- V-238105 Medium The ability to store user passwords in Skype must be disabled.
- V-238106 Medium Session Initiation Protocol (SIP) security mode must be configured.
- V-238107 Medium In the event a secure Session Initiation Protocol (SIP) connection fails, the connection must be restricted from resorting to the unencrypted HTTP.
- V-279949 High The version of Skype running on the system must be a supported version.
Removed rules 3
- V-70901 Medium The ability to store user passwords in Skype must be disabled.
- V-70903 Medium Session Initiation Protocol (SIP) security mode must be configured.
- V-70905 Medium In the event a secure Session Initiation Protocol (SIP) connection fails, the connection must be restricted from resorting to the unencrypted HTTP.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- DTOO420
- Vuln IDs
-
- V-238105
- V-70901
- Rule IDs
-
- SV-238105r961863_rule
- SV-85525
Checks: C-41315r651436_chk
Verify the policy value for Computer Configuration -> Administrative Templates -> Skype for Business 2016 -> Microsoft Lync Feature Policies "Allow storage of user passwords" is set to "Disabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\office\16.0\lync Criteria: If the value savepassword is REG_DWORD = 0, this is not a finding.
Fix: F-41274r651437_fix
Set the policy value for Computer Configuration -> Administrative Templates -> Skype for Business 2016 -> Microsoft Lync Feature Policies "Allow storage of user passwords" to "Disabled".
- RMF Control
- SC-23
- Severity
- M
- CCI
- CCI-001184
- Version
- DTOO421
- Vuln IDs
-
- V-238106
- V-70903
- Rule IDs
-
- SV-238106r1043178_rule
- SV-85527
Checks: C-41316r651439_chk
Verify the policy value for Computer Configuration -> Administrative Templates -> Skype for Business 2016 -> Microsoft Lync Feature Policies "Configure SIP security mode" is set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\office\16.0\lync Criteria: If the value enablesiphighsecuritymode is REG_DWORD = 1, this is not a finding.
Fix: F-41275r651440_fix
Set the policy value for Computer Configuration -> Administrative Templates -> Skype for Business 2016 -> Microsoft Lync Feature Policies "Configure SIP security mode" to "Enabled".
- RMF Control
- SC-23
- Severity
- M
- CCI
- CCI-001184
- Version
- DTOO422
- Vuln IDs
-
- V-238107
- V-70905
- Rule IDs
-
- SV-238107r1043178_rule
- SV-85529
Checks: C-41317r651442_chk
Verify the policy value for Computer Configuration -> Administrative Templates -> Skype for Business 2016 -> Microsoft Lync Feature Policies "Disable HTTP fallback for SIP connection" is set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\office\16.0\lync Criteria: If the value disablehttpconnect is REG_DWORD = 1, this is not a finding.
Fix: F-41276r651443_fix
Set the policy value for Computer Configuration -> Administrative Templates -> Skype for Business 2016 -> Microsoft Lync Feature Policies "Disable HTTP fallback for SIP connection" to "Enabled".
- RMF Control
- SI-2
- Severity
- H
- CCI
- CCI-002605
- Version
- DTOSkype999
- Vuln IDs
-
- V-279949
- Rule IDs
-
- SV-279949r1156596_rule
Checks: C-84510r1156594_chk
Skype is no longer supported by the vendor. If the system is running Skype, this is a finding.
Fix: F-84415r1156595_fix
Upgrade to a supported version.