Voice Video Endpoint Security Requirements Guide
Pick two releases to diff their requirements.
Open a previous version of this STIG.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SRG-NET-000512-VVEP-00001
- Vuln IDs
-
- V-66683
- Rule IDs
-
- SV-81173r1_rule
Checks: C-67309r1_chk
If the Voice Video Endpoint is not a hardware endpoint, this check procedure is Not Applicable. Verify the hardware Voice Video Endpoint integrates into the implemented 802.1x network access control system. If the hardware Voice Video Endpoint does not integrate into the implemented 802.1x network access control system, this is a finding.
Fix: F-72759r1_fix
Configure the hardware Voice Video Endpoint to integrate into the implemented 802.1x network access control system.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SRG-NET-000512-VVEP-00002
- Vuln IDs
-
- V-66685
- Rule IDs
-
- SV-81175r1_rule
Checks: C-67311r1_chk
If the Voice Video Endpoint is not a hardware endpoint, this check procedure is Not Applicable. If an 802.1x network access control system is not implemented on the network, this is Not Applicable. Verify the hardware Voice Video Endpoint is an 802.1x supplicant. If the hardware Voice Video Endpoint is not an 802.1x supplicant, this is a finding.
Fix: F-72761r1_fix
Configure the hardware Voice Video Endpoint to be an 802.1x supplicant in the implemented 802.1x network access control system.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SRG-NET-000512-VVEP-00003
- Vuln IDs
-
- V-66687
- Rule IDs
-
- SV-81177r1_rule
Checks: C-67313r1_chk
If the Voice Video Endpoint is not a hardware endpoint with a PC port, this check procedure is Not Applicable. Verify the hardware Voice Video Endpoint PC port connects to an 802.1x supplicant or is disabled. If the hardware Voice Video Endpoint PC port is disabled, this is not a finding. If the hardware Voice Video Endpoint PC port is not disabled and is not an 802.1x authenticator, this is a finding.
Fix: F-72763r1_fix
Configure the hardware Voice Video Endpoint PC port to connect to an 802.1x supplicant in the implemented 802.1x network access control system or be disabled.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SRG-NET-000512-VVEP-00004
- Vuln IDs
-
- V-66689
- Rule IDs
-
- SV-81179r1_rule
Checks: C-67315r1_chk
If the Voice Video Endpoint is not a hardware endpoint with a PC port, this check procedure is Not Applicable. Verify the unused hardware Voice Video Endpoint PC port is disabled. If the unused hardware Voice Video Endpoint PC port is not disabled, this is a finding.
Fix: F-72765r1_fix
Configure the unused hardware Video Endpoint PC port to be disabled.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SRG-NET-000512-VVEP-00005
- Vuln IDs
-
- V-66691
- Rule IDs
-
- SV-81181r1_rule
Checks: C-67317r1_chk
If the Voice Video Endpoint is not a hardware endpoint with a PC port, this check procedure is Not Applicable. Verify the hardware Voice Video Endpoint with a PC port has the switchport configured as single-host or enable 802.1x multi-domain authentication. If the hardware Voice Video Endpoint with a PC port has the switchport configured as single-host, this is not a finding. If the hardware Voice Video Endpoint with a PC port does not have the switchport configured as single-host and does not enable 802.1x multi-domain authentication, this is a finding.
Fix: F-72767r1_fix
Configure the hardware Voice Video Endpoint with a PC port to have the switchport configured as single-host or enable 802.1x multi-domain authentication.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SRG-NET-000512-VVEP-00006
- Vuln IDs
-
- V-66693
- Rule IDs
-
- SV-81183r1_rule
Checks: C-67319r1_chk
If the Voice Video Endpoint is not a hardware endpoint, this check procedure is Not Applicable. Verify the hardware Voice Video Endpoint not supporting 802.1x is configured to use MAB on the access switchport. If the hardware Voice Video Endpoint not supporting 802.1x is not configured to use MAB on the access switchport, this is a finding.
Fix: F-72769r1_fix
Configure the hardware Voice Video Endpoint not supporting 802.1x to use MAB on the access switchport.
- RMF Control
- IA-11
- Severity
- M
- CCI
- CCI-002039
- Version
- SRG-NET-000338-VVEP-00007
- Vuln IDs
-
- V-66695
- Rule IDs
-
- SV-81185r1_rule
Checks: C-67321r1_chk
If the Voice Video Endpoint is not a hardware endpoint, this check procedure is Not Applicable. Verify the hardware Voice Video Endpoint reauthenticates 802.1x or MAB every three hours or less. If the hardware Voice Video Endpoint does not reauthenticate 802.1x or MAB every three hours or less, this is a finding.
Fix: F-72771r1_fix
Configure the hardware Voice Video Endpoint to reauthenticate 802.1x or MAB every three hours or less.
- RMF Control
- SC-8
- Severity
- M
- CCI
- CCI-002418
- Version
- SRG-NET-000371-VVEP-00008
- Vuln IDs
-
- V-66697
- Rule IDs
-
- SV-81187r2_rule
Checks: C-67323r1_chk
If the Voice Video Endpoint is not a hardware endpoint, this check procedure is Not Applicable. Verify the hardware Voice Video Endpoint uses MACsec to protect the confidentiality and integrity of transmitted information. If the hardware Voice Video Endpoint does not implement MACsec to protect the confidentiality and integrity of transmitted information, this is a finding.
Fix: F-72773r1_fix
Configure the hardware Voice Video Endpoint to implement MACsec to protect the confidentiality and integrity of transmitted information.
- RMF Control
- AC-10
- Severity
- M
- CCI
- CCI-000054
- Version
- SRG-NET-000053-VVEP-00009
- Vuln IDs
-
- V-66699
- Rule IDs
-
- SV-81189r1_rule
Checks: C-67325r1_chk
Verify the Voice Video Endpoint limits the number of concurrent sessions to two users. Local policy may justify and increase the limit on concurrent user sessions to a number higher than two. If the Voice Video Endpoint does not limit the number of concurrent sessions to two users, or the limit set by local policy, this is a finding.
Fix: F-72775r1_fix
Configure the Voice Video Endpoint to limit the number of concurrent sessions to two users or the limit set by local policy.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SRG-NET-000520-VVEP-00010
- Vuln IDs
-
- V-66701
- Rule IDs
-
- SV-81191r1_rule
Checks: C-67327r1_chk
If the Voice Video Endpoint is not a hardware endpoint, this check procedure is Not Applicable. Verify the hardware Voice Video Endpoint applies 802.1Q VLAN tags to signaling and media traffic. If the hardware Voice Video Endpoint does not apply 802.1Q VLAN tags to signaling and media traffic, this is a finding.
Fix: F-72777r1_fix
Configure the hardware Voice Video Endpoint to apply 802.1Q VLAN tags to signaling and media traffic.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SRG-NET-000520-VVEP-00011
- Vuln IDs
-
- V-66703
- Rule IDs
-
- SV-81193r1_rule
Checks: C-67329r1_chk
If the Voice Video Endpoint is not a hardware endpoint, this check procedure is Not Applicable. Verify the hardware Voice Video Endpoint implements a voice video VLAN separate from the default VLAN, the management VLAN, and the data VLAN. For networks with both VoIP and videoconferencing, best practice is to have a separate voice VLAN and video VLAN. If the hardware Voice Video Endpoint does not implement a voice video VLAN separate from the default VLAN, the management VLAN, and the data VLAN, this is a finding.
Fix: F-72779r1_fix
Configure the hardware Voice Video Endpoint to use a voice video VLAN separate from the default VLAN, the management VLAN, and the data VLAN.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SRG-NET-000057-VVEP-00012
- Vuln IDs
-
- V-66705
- Rule IDs
-
- SV-81195r1_rule
Checks: C-67331r1_chk
If the Voice Video Endpoint is not a hardware endpoint, this check procedure is Not Applicable. Verify the hardware Voice Video Endpoint PC port maintains VLAN separation from the voice video VLAN or is disabled. For networks with both VoIP and videoconferencing, best practice is to have a separate voice VLAN and video VLAN. If the hardware Voice Video Endpoint PC port is disabled, this is not a finding. If the hardware Voice Video Endpoint PC port does not maintain VLAN separation from the voice video VLAN, this is a finding.
Fix: F-72781r1_fix
Configure the hardware Voice Video Endpoint PC port to maintain VLAN separation from the voice video VLAN or be disabled.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SRG-NET-000366-VVEP-00014
- Vuln IDs
-
- V-66707
- Rule IDs
-
- SV-81197r1_rule
Checks: C-67333r1_chk
If UC and VC clients cannot be independently configured by either end users or external service providers, this is Not Applicable. Verify the Voice Video Endpoint blocks both inbound and outbound communications traffic between UC and VC clients independently configured by end users and external service providers for voice and video. If the Voice Video Endpoint does not block both inbound and outbound communications traffic between UC and VC clients independently configured by end users and external service providers, this is a finding.
Fix: F-72783r1_fix
Configure the Voice Video Endpoint to block both inbound and outbound communications traffic between UC and VC clients independently configured by end users and external service providers.
- RMF Control
- IA-2
- Severity
- M
- CCI
- CCI-001942
- Version
- SRG-NET-000147-VVEP-00015
- Vuln IDs
-
- V-66709
- Rule IDs
-
- SV-81199r1_rule
Checks: C-67335r1_chk
Verify the Voice Video Endpoint implements replay-resistant authentication mechanisms for network access. If the Voice Video Endpoint does not implement replay-resistant authentication mechanisms for network access, this is a finding.
Fix: F-72785r1_fix
Configure the Voice Video Endpoint to implement replay-resistant authentication mechanisms for network access.
- RMF Control
- IA-2
- Severity
- M
- CCI
- CCI-001942
- Version
- SRG-NET-000147-VVEP-00016
- Vuln IDs
-
- V-66711
- Rule IDs
-
- SV-81201r1_rule
Checks: C-67337r1_chk
If the Voice Video Endpoint is not a hardware endpoint, this check procedure is Not Applicable. Verify the hardware Voice Video Endpoint using SIP or AS-SIP signaling prevents cross-site scripting attacks caused by improper filtering or validation of the content of SIP invitation fields. If the hardware Voice Video Endpoint does not use SIP or AS-SIP, this is not a finding. If the hardware Voice Video Endpoint does not prevent cross-site scripting attacks caused by improper filtering or validation of the content of SIP invitation fields, this is a finding.
Fix: F-72787r1_fix
Configure the hardware Voice Video Endpoint using SIP or AS-SIP signaling to prevent cross-site scripting attacks caused by improper filtering or validation of the content of SIP invitation fields.
- RMF Control
- SC-8
- Severity
- M
- CCI
- CCI-002418
- Version
- SRG-NET-000371-VVEP-00017
- Vuln IDs
-
- V-66713
- Rule IDs
-
- SV-81203r2_rule
Checks: C-67339r1_chk
Verify the Voice Video Endpoint protects the integrity of transmitted configuration files from the Voice Video Session Manager. If the Voice Video Endpoint does not protect the integrity of transmitted configuration files from the Voice Video Session Manager, this is a finding.
Fix: F-72789r1_fix
Configure the Voice Video Endpoint to protect the integrity of transmitted configuration files from the Voice Video Session Manager.
- RMF Control
- SC-8
- Severity
- M
- CCI
- CCI-002418
- Version
- SRG-NET-000371-VVEP-00018
- Vuln IDs
-
- V-66715
- Rule IDs
-
- SV-81205r2_rule
Checks: C-67341r1_chk
Verify the Voice Video Endpoint protects the confidentiality of transmitted configuration files from the Voice Video Session Manager. If the Voice Video Endpoint does not protect the confidentiality of transmitted configuration files from the Voice Video Session Manager, this is a finding.
Fix: F-72791r1_fix
Configure the Voice Video Endpoint to protect the confidentiality of transmitted configuration files from the Voice Video Session Manager.
- RMF Control
- AC-3
- Severity
- M
- CCI
- CCI-000213
- Version
- SRG-NET-000015-VVEP-00019
- Vuln IDs
-
- V-66717
- Rule IDs
-
- SV-81207r1_rule
Checks: C-67343r1_chk
Verify the Voice Video Endpoint dynamically implements configuration file changes. If the Voice Video Endpoint does not dynamically implement configuration file changes, this is a finding.
Fix: F-72793r1_fix
Configure the Voice Video Endpoint to dynamically implement configuration file changes.
- RMF Control
- AC-8
- Severity
- M
- CCI
- CCI-000048
- Version
- SRG-NET-000041-VVEP-00020
- Vuln IDs
-
- V-66719
- Rule IDs
-
- SV-81209r1_rule
Checks: C-67345r2_chk
If the Voice Video Endpoint is a hardware endpoint, this is Not Applicable. For unclassified VoIP hardware endpoints, a DD FORM 2056 or other approved consent to monitoring sticker should be affixed. If the Voice Video Endpoint is a software client, verify the Voice Video Endpoint displays the Standard Mandatory DoD Notice and Consent Banner before granting access to the network. If the Voice Video Endpoint does not display the Standard Mandatory DoD Notice and Consent Banner before granting access to the network, this is a finding.
Fix: F-72795r1_fix
Configure the Voice Video Endpoint to display the Standard Mandatory DoD Notice and Consent Banner before granting access to the network.
- RMF Control
- AC-8
- Severity
- M
- CCI
- CCI-000050
- Version
- SRG-NET-000042-VVEP-00021
- Vuln IDs
-
- V-66725
- Rule IDs
-
- SV-81215r1_rule
Checks: C-67375r2_chk
If the Voice Video Endpoint is a hardware endpoint, this is Not Applicable. For unclassified VoIP hardware endpoints, a DD FORM 2056 or other approved consent to monitoring sticker should be affixed. If the Voice Video Endpoint is a software client, verify the Voice Video Endpoint retains the Standard Mandatory DoD Notice and Consent Banner on the screen until users acknowledge the usage conditions and take explicit actions to log on for further access. If the Voice Video Endpoint does not retain the Standard Mandatory DoD Notice and Consent Banner on the screen until users take explicit actions to log on for further access, this is a finding.
Fix: F-72825r1_fix
Configure the Voice Video Endpoint to retain the Standard Mandatory DoD Notice and Consent Banner on the screen until users acknowledge the usage conditions and take explicit actions to log on for further access.
- RMF Control
- AU-3
- Severity
- M
- CCI
- CCI-000130
- Version
- SRG-NET-000074-VVEP-00022
- Vuln IDs
-
- V-66727
- Rule IDs
-
- SV-81217r1_rule
Checks: C-67377r1_chk
If the Voice Video Endpoint relies exclusively on the Voice Video Session Manager for session records and does not have any capability for generating session records, this check procedure is Not Applicable. Verify the Voice Video Endpoint produces session records containing what type of connection occurred. The record must include the session type (voice/direct, voice/conference, video/direct, video/conference, etc.), the specific protocols used for control and media traffic (SIP/SRTP, H.323, etc.), and the type of endpoint (mobile, telephone, codec, etc.). If the Voice Video Endpoint does not produce session records containing what type of connection occurred, this is a finding.
Fix: F-72827r1_fix
Configure the Voice Video Endpoint to produce session records containing what type of connection occurred.
- RMF Control
- AU-3
- Severity
- M
- CCI
- CCI-000131
- Version
- SRG-NET-000075-VVEP-00023
- Vuln IDs
-
- V-66729
- Rule IDs
-
- SV-81219r1_rule
Checks: C-67379r1_chk
If the Voice Video Endpoint relies exclusively on the Voice Video Session Manager for session records and does not have any capability for generating session records, this check procedure is Not Applicable. Verify the Voice Video Endpoint produces session records containing when the connection occurred. The record must include session start/join/leave/stop times. If the Voice Video Endpoint does not produce session records containing the date and time when the connection occurred, this is a finding.
Fix: F-72829r1_fix
Configure the Voice Video Endpoint to produce session records containing the date and time when the connection occurred.
- RMF Control
- AU-3
- Severity
- M
- CCI
- CCI-000132
- Version
- SRG-NET-000076-VVEP-00024
- Vuln IDs
-
- V-66731
- Rule IDs
-
- SV-81221r1_rule
Checks: C-67381r1_chk
If the Voice Video Endpoint relies exclusively on the Voice Video Session Manager for session records and does not have any capability for generating session records, this check procedure is Not Applicable. Verify the Voice Video Endpoint produces session records containing where the connection occurred. The record must include IP addresses and port numbers. If the Voice Video Endpoint does not produce session records containing where the connection occurred, this is a finding.
Fix: F-72831r1_fix
Configure the Voice Video Endpoint to produce session records containing where the connection occurred.
- RMF Control
- AU-3
- Severity
- M
- CCI
- CCI-000134
- Version
- SRG-NET-000078-VVEP-00025
- Vuln IDs
-
- V-66733
- Rule IDs
-
- SV-81223r1_rule
Checks: C-67383r1_chk
If the Voice Video Endpoint relies exclusively on the Voice Video Session Manager for session records and does not have any capability for generating session records, this check procedure is Not Applicable. Verify the Voice Video Endpoint produces session records containing the outcome of the connection. Outcomes of the connection would include call completed, conference completed, destination busy, network busy, etc. If the Voice Video Endpoint does not produce session records containing the outcome of the connection, this is a finding.
Fix: F-72833r1_fix
Configure the Voice Video Endpoint to produce session records containing the outcome of the connection.
- RMF Control
- AU-3
- Severity
- M
- CCI
- CCI-001487
- Version
- SRG-NET-000079-VVEP-00026
- Vuln IDs
-
- V-66735
- Rule IDs
-
- SV-81225r1_rule
Checks: C-67385r1_chk
If the Voice Video Endpoint relies exclusively on the Voice Video Session Manager for session records and does not have any capability for generating session records, this check procedure is Not Applicable. Verify the Voice Video Endpoint produces session records containing the identity of all users on the call. If the Voice Video Endpoint does not produce session records containing the identity of all users on the call, this is a finding.
Fix: F-72835r1_fix
Configure the Voice Video Endpoint to produce session records containing the identity of all users on the call.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000169
- Version
- SRG-NET-000113-VVEP-00027
- Vuln IDs
-
- V-66737
- Rule IDs
-
- SV-81227r1_rule
Checks: C-67387r1_chk
If the Voice Video Endpoint relies exclusively on the Voice Video Session Manager for session records and does not have any capability for generating session records, this check procedure is Not Applicable. Verify the Voice Video Endpoint provides session record generation capability. If the Voice Video Endpoint does not provide session record generation capability, this is a finding.
Fix: F-72837r1_fix
Configure the Voice Video Endpoint to provide session record generation capability.
- RMF Control
- SC-10
- Severity
- M
- CCI
- CCI-001133
- Version
- SRG-NET-000213-VVEP-00028
- Vuln IDs
-
- V-66739
- Rule IDs
-
- SV-81229r1_rule
Checks: C-67389r1_chk
Verify the Voice Video Endpoint terminates all network connections associated with a communications session at the end of the session. If the Voice Video Endpoint does not terminate all network connections associated with a communications session at the end of the session, this is a finding.
Fix: F-72839r1_fix
Configure the Voice Video Endpoint to terminate all network connections associated with a communications session at the end of the session.
- RMF Control
- IA-2
- Severity
- M
- CCI
- CCI-000764
- Version
- SRG-NET-000138-VVEP-00029
- Vuln IDs
-
- V-66741
- Rule IDs
-
- SV-81231r1_rule
Checks: C-67391r1_chk
Verify the Voice Video Endpoint used for videoconferencing uniquely identifies participating users. Identification must be visible and displayed locally. If the Voice Video Endpoint used for videoconferencing does not uniquely identify participating users, this is a finding.
Fix: F-72841r1_fix
Configure the Voice Video Endpoint used for videoconferencing to uniquely identify participating users.
- RMF Control
- IA-2
- Severity
- M
- CCI
- CCI-001953
- Version
- SRG-NET-000341-VVEP-00030
- Vuln IDs
-
- V-66743
- Rule IDs
-
- SV-81233r1_rule
Checks: C-67393r1_chk
If the Voice Video Endpoint is a hardware endpoint, this check procedure is Not Applicable. Verify the Voice Video Endpoint used for videoconferencing accepts a CAC or derived credentials. For hardware endpoints, the devices must use certificates to register with the session manager or multipoint controller. If the Voice Video Endpoint used for videoconferencing does not accept a CAC or derived credentials, this is a finding.
Fix: F-72843r1_fix
Configure the Voice Video Endpoint used for videoconferencing to accept a CAC or derived credentials.
- RMF Control
- IA-2
- Severity
- M
- CCI
- CCI-001954
- Version
- SRG-NET-000342-VVEP-00031
- Vuln IDs
-
- V-66745
- Rule IDs
-
- SV-81235r1_rule
Checks: C-67395r1_chk
If the Voice Video Endpoint is a hardware endpoint, this check procedure is Not Applicable. Verify the Voice Video Endpoint used for videoconferencing electronically verifies the CAC or derived credentials. For hardware endpoints, the devices must use certificates to register with the session manager or multipoint controller. If the Voice Video Endpoint used for videoconferencing does not electronically verify the CAC or derived credentials, this is a finding.
Fix: F-72845r1_fix
Configure the Voice Video Endpoint used for videoconferencing to electronically verify the CAC or derived credentials.
- RMF Control
- IA-2
- Severity
- M
- CCI
- CCI-000766
- Version
- SRG-NET-000140-VVEP-00032
- Vuln IDs
-
- V-66747
- Rule IDs
-
- SV-81237r1_rule
Checks: C-67397r1_chk
If the Voice Video Endpoint is not a hardware endpoint, this check procedure is Not Applicable. Verify the Voice Video Endpoint used for videoconferencing uses multifactor authentication for network access. For hardware endpoints, the devices must use certificates to register with the session manager or multipoint controller. If the Voice Video Endpoint used for videoconferencing does not use multifactor authentication for network access, this is a finding.
Fix: F-72847r1_fix
Configure the Voice Video Endpoint used for videoconferencing to use multifactor authentication for network access.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000197
- Version
- SRG-NET-000400-VVEP-00033
- Vuln IDs
-
- V-66749
- Rule IDs
-
- SV-81239r1_rule
Checks: C-67399r1_chk
Verify the Voice Video Endpoint, when using passwords or PINs for authentication or authorization, cryptographically protects the transmission. If the Voice Video Endpoint, when using passwords or PINs for authentication or authorization, does not cryptographically protect the transmission, this is a finding.
Fix: F-72849r1_fix
Configure the Voice Video Endpoint, when using passwords or PINs for authentication or authorization, to cryptographically protect the transmission.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000186
- Version
- SRG-NET-000165-VVEP-00034
- Vuln IDs
-
- V-66751
- Rule IDs
-
- SV-81241r1_rule
Checks: C-67401r1_chk
Verify the Voice Video Endpoint, when using PKI-based authentication, enforces authorized access only to the corresponding private key. If the Voice Video Endpoint, when using PKI-based authentication, does not enforce authorized access to the corresponding private key, this is a finding.
Fix: F-72851r1_fix
Configure the Voice Video Endpoint, when using PKI-based authentication, to enforce authorized access to the corresponding private key.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000185
- Version
- SRG-NET-000164-VVEP-00035
- Vuln IDs
-
- V-66753
- Rule IDs
-
- SV-81243r1_rule
Checks: C-67403r1_chk
Verify the Voice Video Endpoint used for videoconferencing, when using PKI-based authentication, validates certificates by constructing a certification path to an accepted trust anchor. The constructed certification path must include status information. If the Voice Video Endpoint used for videoconferencing, when using PKI-based authentication, does not validate certificates by constructing a certification path that includes status information to an accepted trust anchor, this is a finding.
Fix: F-72853r1_fix
Configure the Voice Video Endpoint used for videoconferencing, when using PKI-based authentication, to validate certificates by constructing a certification path, including status information, to an accepted trust anchor.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-001991
- Version
- SRG-NET-000345-VVEP-00036
- Vuln IDs
-
- V-66755
- Rule IDs
-
- SV-81245r1_rule
Checks: C-67405r1_chk
Verify the Voice Video Endpoint used for videoconferencing, when using PKI-based authentication, implements a local cache of revocation data to support path discovery and validation in the event the network path becomes unavailable. If the Voice Video Endpoint used for videoconferencing, when using PKI-based authentication, does not implement a local cache of revocation data to support path discovery and validation in the event the network path becomes unavailable, this is a finding.
Fix: F-72855r1_fix
Configure the Voice Video Endpoint used for videoconferencing, when using PKI-based authentication, to implement a local cache of revocation data to support path discovery and validation in the event the network path becomes unavailable.
- RMF Control
- SC-8
- Severity
- M
- CCI
- CCI-002418
- Version
- SRG-NET-000371-VVEP-00037
- Vuln IDs
-
- V-66757
- Rule IDs
-
- SV-81247r2_rule
Checks: C-67407r1_chk
Verify the Voice Video Endpoint uses encryption for signaling and media traffic. If the Voice Video Endpoint does not use encryption for signaling and media traffic, this is a finding.
Fix: F-72857r1_fix
Configure the Voice Video Endpoint to use encryption for signaling and media traffic.
- RMF Control
- SC-13
- Severity
- M
- CCI
- CCI-002450
- Version
- SRG-NET-000352-VVEP-00038
- Vuln IDs
-
- V-66759
- Rule IDs
-
- SV-81249r1_rule
Checks: C-67409r1_chk
Verify the Voice Video Endpoint processing classified information over public networks implements NSA-approved cryptography. If the Voice Video Endpoint processing classified information over public networks does not implement NSA-approved cryptography, this is a finding.
Fix: F-72859r1_fix
Configure the Voice Video Endpoint processing classified information over public networks to implement NSA-approved cryptography.
- RMF Control
- SC-13
- Severity
- M
- CCI
- CCI-002450
- Version
- SRG-NET-000510-VVEP-00039
- Vuln IDs
-
- V-66761
- Rule IDs
-
- SV-81251r1_rule
Checks: C-67411r1_chk
Verify the Voice Video Endpoint processing unclassified information implements NIST FIPS-validated cryptography. If the Voice Video Endpoint processing unclassified information does not implement NIST FIPS-validated cryptography, this is a finding.
Fix: F-72861r1_fix
Configure the Voice Video Endpoint processing unclassified information to implement NIST FIPS-validated cryptography.
- RMF Control
- SC-13
- Severity
- M
- CCI
- CCI-002450
- Version
- SRG-NET-000510-VVEP-00041
- Vuln IDs
-
- V-66763
- Rule IDs
-
- SV-81253r1_rule
Checks: C-67413r1_chk
Verify the Voice Video Endpoint processing unclassified information implements NIST FIPS-validated cryptography to generate cryptographic hashes. If the Voice Video Endpoint processing unclassified information does not implement NIST FIPS-validated cryptography to generate cryptographic hashes, this is a finding.
Fix: F-72863r1_fix
Configure the Voice Video Endpoint processing unclassified information to implement NIST FIPS-validated cryptography to generate cryptographic hashes.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SRG-NET-000353-VVEP-00042
- Vuln IDs
-
- V-66765
- Rule IDs
-
- SV-81255r1_rule
Checks: C-67415r1_chk
Verify the Voice Video Endpoint provides an explicit indication of current participants in all VC-based and IP-based online meetings and conferences. This excludes audio-only teleconferences using traditional telephony. If the Voice Video Endpoint does not provide an explicit indication of current participants in all VC-based and IP-based online meetings and conferences, this is a finding.
Fix: F-72865r1_fix
Configure the Voice Video Endpoint provides an explicit indication of current participants in all VC-based and IP-based online meetings and conferences.
- RMF Control
- SC-24
- Severity
- M
- CCI
- CCI-001665
- Version
- SRG-NET-000236-VVEP-00043
- Vuln IDs
-
- V-66767
- Rule IDs
-
- SV-81257r1_rule
Checks: C-67417r1_chk
If the Voice Video Endpoint is not a hardware endpoint, this check procedure is Not Applicable. Verify that in the event of device failure, the hardware Voice Video Endpoint preserves any information necessary to determine cause of failure and return to operations with least disruption to service. If the hardware Voice Video Endpoint does not preserve any information necessary to determine cause of failure, this is a finding. If the hardware Voice Video Endpoint does not return to operations with least disruption to service after device failure, this is a finding.
Fix: F-72867r1_fix
Configure the hardware Voice Video Endpoint, in the event of device failure, to preserve any information necessary to determine cause of failure. Also configure the hardware Voice Video Endpoint to return to operations with least disruption to service.
- RMF Control
- SC-4
- Severity
- M
- CCI
- CCI-001090
- Version
- SRG-NET-000190-VVEP-00044
- Vuln IDs
-
- V-66769
- Rule IDs
-
- SV-81259r1_rule
Checks: C-67419r1_chk
Verify the Voice Video Endpoint prevents unauthorized and unintended information transfer via shared system resources. If the Voice Video Endpoint does not prevent unauthorized and unintended information transfer via shared system resources, this is a finding.
Fix: F-72869r1_fix
Configure the Voice Video Endpoint to prevent unauthorized and unintended information transfer via shared system resources.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SRG-NET-000512-VVEP-00045
- Vuln IDs
-
- V-66771
- Rule IDs
-
- SV-81261r1_rule
Checks: C-67421r1_chk
If the Voice Video Endpoint does not support C2 communications, this check procedure is Not Applicable. Verify the Voice Video Endpoint supporting C2 communications implements MLPP dialing to enable Routine, Priority, Immediate, Flash, and Flash Override. If the Voice Video Endpoint supporting C2 communications does not implement MLPP dialing to enable Routine, Priority, Immediate, Flash, and Flash Override, this is a finding. If the MLPP dialing is not configured, this is a finding.
Fix: F-72871r1_fix
Configure the Voice Video Endpoint supporting C2 communications to implement MLPP dialing to enable Routine, Priority, Immediate, Flash, and Flash Override.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SRG-NET-000512-VVEP-00046
- Vuln IDs
-
- V-66773
- Rule IDs
-
- SV-81263r1_rule
Checks: C-67423r1_chk
If the Voice Video Endpoint does not support C2 communications, this check procedure is Not Applicable. Verify the Voice Video Endpoint supporting C2 communications implements MLPP call disconnect to enable Routine, Priority, Immediate, Flash, and Flash Override. If the Voice Video Endpoint supporting C2 communications does not implement MLPP call disconnect to enable Routine, Priority, Immediate, Flash, and Flash Override, this is a finding. If the MLPP call disconnect is not configured for use, this is a finding.
Fix: F-72873r1_fix
Configure the Voice Video Endpoint supporting C2 communications to implement MLPP call disconnect to enable Routine, Priority, Immediate, Flash, and Flash Override.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SRG-NET-000512-VVEP-00047
- Vuln IDs
-
- V-66775
- Rule IDs
-
- SV-81265r1_rule
Checks: C-67425r1_chk
If the Voice Video Endpoint does not support C2 communications, this check procedure is Not Applicable. Verify the Voice Video Endpoint supporting C2 communications implements AS-SIP. If the Voice Video Endpoint supporting C2 communications does not implement AS-SIP, this is a finding. If AS-SIP is not configured for use, this is a finding.
Fix: F-72875r1_fix
Configure the Voice Video Endpoint supporting C2 communications to implement AS-SIP.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SRG-NET-000512-VVEP-00048
- Vuln IDs
-
- V-66777
- Rule IDs
-
- SV-81267r1_rule
Checks: C-67427r1_chk
Verify the Voice Video Endpoint microphone provides hardware mechanisms, such as push-to-talk handset switches, to prevent pickup and transmission of sensitive or classified information over non-secure networks. If the Voice Video Endpoint microphone does not provide hardware mechanisms, such as push-to-talk handset switches, to prevent pickup and transmission of sensitive or classified information over non-secure networks, this is a finding. If the Voice Video Endpoint microphone does provide hardware mechanisms but is not configured to use these features, this is a finding.
Fix: F-72877r1_fix
Configure the Voice Video Endpoint microphone hardware mechanisms, such as push-to-talk handset switches, to prevent pickup and transmission of sensitive or classified information over non-secure networks.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SRG-NET-000512-VVEP-00049
- Vuln IDs
-
- V-66779
- Rule IDs
-
- SV-81269r1_rule
Checks: C-67429r1_chk
Verify the Voice Video Endpoint camera provides hardware mechanisms, such as push-to-see camera switches, to prevent pickup and transmission of sensitive or classified information over non-secure networks. If the Voice Video Endpoint camera does not provide hardware mechanisms, such as push-to-see camera switches, to prevent pickup and transmission of sensitive or classified information over non-secure networks, this is a finding. If the Voice Video Endpoint camera does provide hardware mechanisms but is not configured to use these features, this is a finding.
Fix: F-72879r1_fix
Configure the Voice Video Endpoint camera hardware mechanisms, such as push-to-see camera switches, to prevent pickup and transmission of sensitive or classified information over non-secure networks.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SRG-NET-000512-VVEP-00050
- Vuln IDs
-
- V-66781
- Rule IDs
-
- SV-81271r1_rule
Checks: C-67431r1_chk
Verify the Voice Video Endpoint auto-answer feature is disabled. If the Voice Video Endpoint auto-answer feature is not disabled, this is a finding.
Fix: F-72881r1_fix
Configure the Voice Video Endpoint auto-answer feature to be disabled.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SRG-NET-000512-VVEP-00051
- Vuln IDs
-
- V-66783
- Rule IDs
-
- SV-81273r1_rule
Checks: C-67433r1_chk
If the Voice Video Endpoint is not a hardware endpoint, this check procedure is Not Applicable. Verify the hardware Voice Video Endpoint disables or restricts web browser capabilities permitting the endpoint to browse the Internet or intranet. External applications and services approved for accessibility on the Voice Video Endpoint and implemented by the enterprise are permissible. If the hardware Voice Video does not disable or restrict web browser capabilities permitting the endpoint to browse the Internet or intranet, this is a finding.
Fix: F-72883r1_fix
Configure the hardware Voice Video Endpoint to disable or restrict web browser capabilities permitting the endpoint to browse the Internet or intranet.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SRG-NET-000512-VVEP-00052
- Vuln IDs
-
- V-66785
- Rule IDs
-
- SV-81275r1_rule
Checks: C-67435r1_chk
If the Voice Video Endpoint is not a hardware endpoint, this check procedure is Not Applicable. If the hardware Voice Video Endpoint does not contain a web server, this check procedure is Not Applicable. Verify the hardware Voice Video Endpoint disables or restricts built-in web servers. Web servers embedded in hardware Voice Video Endpoints must be restricted to authorized entities’ devices through an authentication mechanism or, minimally, through IP address filtering, or be otherwise disabled. Additionally, the connection must be for direct user or administrative functions. If the hardware Voice Video Endpoint does not disable or restrict built-in web servers, this is a finding.
Fix: F-72885r1_fix
Configure the hardware Voice Video Endpoint to disable or restrict built-in web servers.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SRG-NET-000512-VVEP-00053
- Vuln IDs
-
- V-66787
- Rule IDs
-
- SV-81277r1_rule
Checks: C-67437r1_chk
If the Voice Video Endpoint is not a hardware endpoint, this check procedure is Not Applicable. Verify the hardware Voice Video Endpoint prevents the configuration of network IP settings without the use of a PIN or password. If the hardware Voice Video Endpoint does not prevent the configuration of network IP settings without the use of a PIN or password, this is a finding.
Fix: F-72887r1_fix
Configure the hardware Voice Video Endpoint to prevent the configuration of network IP settings without the use of a PIN or password.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SRG-NET-000512-VVEP-00054
- Vuln IDs
-
- V-66789
- Rule IDs
-
- SV-81279r1_rule
Checks: C-67439r1_chk
If the Voice Video Endpoint is not a hardware endpoint, this check procedure is Not Applicable. Verify the hardware Voice Video Endpoint prevents the display of network IP settings without the use of a PIN or password. If the hardware Voice Video Endpoint does not prevent the display of network IP settings without the use of a PIN or password, this is a finding.
Fix: F-72889r1_fix
Configure the hardware Voice Video Endpoint to prevent the display of network IP settings without the use of a PIN or password.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SRG-NET-000512-VVEP-00055
- Vuln IDs
-
- V-66791
- Rule IDs
-
- SV-81281r1_rule
Checks: C-67441r1_chk
If the Voice Video Endpoint is not a hardware endpoint, this check procedure is Not Applicable. Verify the hardware Voice Video Endpoint does not use the default PIN or password to access configuration and display of network IP settings. If the hardware Voice Video Endpoint uses the default PIN or password to access configuration and display of network IP settings, this is a finding.
Fix: F-72891r1_fix
Configure the hardware Voice Video Endpoint to not use the default PIN or password to access configuration and display of network IP settings.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- SRG-NET-000131-VVEP-00056
- Vuln IDs
-
- V-66793
- Rule IDs
-
- SV-81283r1_rule
Checks: C-67443r1_chk
Verify the Voice Video Endpoint is configured to disable or remove non-essential capabilities. Non-essential capabilities would include peer services and other functions not directly pertaining to Voice Video Endpoint functionality. If the Voice Video Endpoint cannot be configured to disable or remove non-essential capabilities, this is a finding.
Fix: F-72893r1_fix
Configure the Voice Video Endpoint to disable or remove non-essential capabilities.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SRG-NET-000512-VVEP-00057
- Vuln IDs
-
- V-66795
- Rule IDs
-
- SV-81285r1_rule
Checks: C-67445r1_chk
Verify the Voice Video Endpoint prevents the user from installing third-party software. If the Voice Video Endpoint does not prevent the user from installing third-party software, this is a finding.
Fix: F-72895r1_fix
Configure the Voice Video Endpoint to prevent the user from installing third-party software.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SRG-NET-000512-VVEP-00058
- Vuln IDs
-
- V-66797
- Rule IDs
-
- SV-81287r1_rule
Checks: C-67447r1_chk
Verify the Voice Video Endpoint prevents installation of untrusted third-party software. If the Voice Video Endpoint does not prevent installation of untrusted third-party software, this is a finding.
Fix: F-72897r1_fix
Configure the Voice Video Endpoint to prevent installation of untrusted third-party software.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000382
- Version
- SRG-NET-000132-VVEP-00059
- Vuln IDs
-
- V-66799
- Rule IDs
-
- SV-81289r1_rule
Checks: C-67449r1_chk
Verify the Voice Video Endpoint only uses ports, protocols, and services allowed per the PPSM CAL and VAs. If the Voice Video Endpoint uses ports, protocols, and services not allowed per the PPSM CAL and VAs, this is a finding.
Fix: F-72899r1_fix
Configure the Voice Video Endpoint to only use ports, protocols, and services allowed per the PPSM CAL and VAs.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SRG-NET-000512-VVEP-00060
- Vuln IDs
-
- V-66801
- Rule IDs
-
- SV-81291r1_rule
Checks: C-67451r1_chk
Verify the Voice Video Endpoint is configured in accordance with the security configuration settings based on DoD security configuration or implementation guidance, including STIGs, NSA configuration guides, CTOs, and DTMs. This requirement is intended to be used to allow best practices and other security guidance to be included within a vendor-produced STIG. If the Voice Video Endpoint is not configured in accordance with the security configuration settings based on DoD security configuration or implementation guidance, including STIGs, NSA configuration guides, CTOs, and DTMs, this is a finding.
Fix: F-72901r1_fix
Configure the Voice Video Endpoint to be configured in accordance with the security configuration settings based on DoD security configuration or implementation guidance, including STIGs, NSA configuration guides, CTOs, and DTMs.
- RMF Control
- SC-13
- Severity
- M
- CCI
- CCI-002450
- Version
- SRG-NET-000510-VVEP-00040
- Vuln IDs
-
- V-66803
- Rule IDs
-
- SV-81293r1_rule
Checks: C-67453r1_chk
Verify the Voice Video Endpoint processing unclassified information implements NIST FIPS-validated cryptography to provision digital signatures. If the Voice Video Endpoint processing unclassified information does not implement NIST FIPS-validated cryptography to provision digital signatures, this is a finding.
Fix: F-72903r1_fix
Configure the Voice Video Endpoint processing unclassified information to implement NIST FIPS-validated cryptography to provision digital signatures.
- RMF Control
- AC-3
- Severity
- M
- CCI
- CCI-000213
- Version
- SRG-NET-000015-VVEP-00013
- Vuln IDs
-
- V-67985
- Rule IDs
-
- SV-82475r1_rule
Checks: C-68545r1_chk
Verify the Voice Video Endpoint registers with a Voice Video Session Manager. If the Voice Video Endpoint does not registers with a Voice Video Session Manager, this is a finding.
Fix: F-74103r1_fix
Configure the Voice Video Endpoint to register with a Voice Video Session Manager.