Select any two versions of this STIG to compare the individual requirements
Select any old version/release of this STIG to view the previous requirements
Verify the Voice Video Session Manager automatically disables Voice Video endpoint user access after a 35 day period of account inactivity. This requirement refers to users rather than endpoints. If the Voice Video Session Manager does not automatically disable Voice Video endpoint user access after a 35 day period of account inactivity, this is a finding.
Configure the Voice Video Session Manager too automatically disable Voice Video endpoint user access after a 35 day period of account inactivity.
Verify the Voice Video Session Manager enforces registration of only approved Voice Video endpoints prior to the endpoints operating with the system. If the Voice Video Session Manager permits registration of unapproved Voice Video endpoints prior to operation, this is a finding.
Configure the Voice Video Session Manager to enforce registration of only approved Voice Video endpoints prior to operating with the system.
Verify the Voice Video Session Manager prevents auto-registration of Voice Video endpoints. During initial system installation and testing, or subsequent large redeployments and additions, it may be necessary to enable auto-registration for a short period. When auto-registration is used under these circumstances, it must be disabled within 5 days and before the system is placed into service. If the Voice Video Session Manager does not disable auto-registration of Voice Video endpoints outside of these conditions, this is a finding.
Configure the Voice Video Session Manager to disable auto-registration of Voice Video endpoints.
Verify the Voice Video Session Manager controls flow within the enclave based on approved dial plans. If the Voice Video Session Manager does not control flow within the enclave based on approved dial plans, this is a finding.
Configure the Voice Video Session Manager to control flow within the enclave based on approved dial plans.
Verify the Voice Video Session Manager controls flow outside the enclave based on approved dial plans. If the Voice Video Session Manager does not control flow outside the enclaves based on approved dial plans, this is a finding.
Configure the Voice Video Session Manager to control flow outside the enclave based on approved dial plans.
Verify the Voice Video Session Manager produces session records containing the type of session connection. If the Voice Video Session Manager does not produce session records containing the type of session connection, this is a finding.
Configure the Voice Video Session Manager to produce session records containing the type of session connection.
Verify the Voice Video Session Manager produces session records containing when (date and time) the connection was established. If the Voice Video Session Manager does not produce session records containing when (date and time) the connection was established, this is a finding.
Configure the Voice Video Session Manager to produce session records containing when (date and time) the connection was established.
Verify the Voice Video Session Manager produces session records containing when (date and time) the connection was terminated. If the Voice Video Session Manager does not produce session records containing when (date and time) the connection was terminated, this is a finding.
Configure the Voice Video Session Manager to produce session records containing when (date and time) the connection was terminated.
Verify the Voice Video Session Manager produces session records containing where (location) the connection originated. If the Voice Video Session Manager does not produce session records containing where (location) the connection originated, this is a finding.
Configure the Voice Video Session Manager to produce session records containing where (location) the connection originated.
Verify the Voice Video Session Manager produces session records containing the identity of the initiator of the call. The identity of the initiator of the call in this context would be the device ID or the address of the MAC or IP. For Voice Video Session Managers that have the concept of a user rather than device, this requirement is not applicable. If the Voice Video Session Manager does not produce session records containing the identity of the initiator of the call, this is a finding.
Configure the Voice Video Session Manager to produce session records containing the identity of the initiator of the call.
Verify the Voice Video Session Manager produces session records containing the outcome (status) of the connection. The outcome or status of a call includes call completed normally, busy endpoint, busy network, preempted, or other pertinent description. If the Voice Video Session Manager does not produce session records containing the outcome (status) of the connection, this is a finding.
Configure the Voice Video Session Manager to produce session records containing the outcome (status) of the connection.
Verify the Voice Video Session Manager produces session records containing the identity of the users and identifiers associated with the session. The identity of the users and identifiers of the call in this context would be the user ID or user name. For Voice Video Session Managers that have the concept of a device rather than users and identifiers, this requirement is not applicable. If the Voice Video Session Manager does not produce session records containing the identity of the users and identifiers associated with the session, this is a finding.
Configure the Voice Video Session Manager to produce session records containing the identity of the users and identifiers associated with the session.
Verify the Voice Video Session Manager alerts the ISSO and SA (at a minimum) in the event of a session record system failure. If the Voice Video Session Manager does not alert the ISSO and SA (at a minimum) in the event of a session record system failure, this is a finding.
Configure the Voice Video Session Manager to alert the ISSO and SA (at a minimum) in the event of a session record system failure.
Verify the Voice Video Session Manager protects session records from unauthorized modification. If the Voice Video Session Manager does not protect session records from unauthorized modification, this is a finding.
Configure the Voice Video Session Manager protect session records from unauthorized modification.
Verify the Voice Video Session Manager protects session records from unauthorized deletion. If the Voice Video Session Manager does not protect session records from unauthorized deletion, this is a finding.
Configure the Voice Video Session Manager to protect session records from unauthorized deletion.
Verify the Voice Video Session Manager produces session records for events determined to be significant and relevant by local policy. If the Voice Video Session Manager does not produce session records for events determined to be significant and relevant by local policy, this is a finding.
Configure the Voice Video Session Manager to produce session records for events determined to be significant and relevant by local policy.
Verify the Voice Video Session Manager is configured to disable non-essential capabilities. If the Voice Video Session Manager is not configured to disable non-essential capabilities, this is a finding.
Configure the Voice Video Session Manager to be configured to disable non-essential capabilities.
Verify the Voice Video Session Manager only uses ports, protocols, and services allowed per the PPSM CAL and VAs. If the Verify the Voice Video Session Manager uses ports, protocols, and services other than those permitted by the PPSM CAL and VAs, this is a finding.
Configure the Voice Video Session Manager to only use of ports, protocols, and services allowed per the PPSM CAL and VAs.
Verify the Voice Video Session Manager implements attack-resistant mechanisms for Voice Video endpoint registration. If the Voice Video Session Manager does not implement attack-resistant mechanisms for Voice Video endpoint registration, this is a finding.
Configure the Voice Video Session Manager to implement attack-resistant mechanisms for Voice Video endpoint registration.
Verify the Voice Video Session Manager uniquely identifies all Voice Video endpoint devices before registration. If the Voice Video Session Manager does not uniquely identify all Voice Video endpoint devices before registration, this is a finding.
Configure the Voice Video Session Manager to uniquely identify all Voice Video endpoint devices before registering those devices.
Verify the Voice Video Session Manager uses encryption for signaling and media traffic. If the Voice Video Session Manager does not use encryption for signaling and media traffic, this is a finding.
Configure the Voice Video Session Manager to use encryption for signaling and media traffic.
Verify the Voice Video Session Manager terminates all network connections associated with a communications session at the end of the session, or the session terminates after 15 minutes of inactivity. If the Voice Video Session Manager does not terminate all network connections associated with a communications session at the end of the session, this is a finding. If the Voice Video Session Manager does not terminate the session after 15 minutes of inactivity, this is a finding.
Configure the Voice Video Session Manager to terminate all network connections associated with a communications session at the end of the session. Alternatively, configure the Voice Video Session Manager to terminate the session after 15 minutes of inactivity.
Verify the Voice Video Session Manager supporting C2 communications associates MLPP attributes when exchanged between UC systems. If the Voice Video Session Manager supporting C2 communications does not associate MLPP attributes when exchanged between UC systems, this is a finding.
Configure the Voice Video Session Manager supporting C2 communications to associate MLPP attributes when exchanged between UC systems.
Verify the Voice Video Session Manager supporting C2 communications validates the integrity of transmitted MLPP attributes. If the Voice Video Session Manager supporting C2 communications does not validate the integrity of transmitted MLPP attributes, this is a finding.
Configure the Voice Video Session Manager supporting C2 communications to validate the integrity of transmitted MLPP attributes.
Verify the Voice Video Session Manager protects the authenticity of communications sessions. If the Voice Video Session Manager does not protect the authenticity of communications sessions, this is a finding.
Configure the Voice Video Session Manager to protect the authenticity of communications sessions.
Verify the Voice Video Session Manager fails to a secure state when system initialization fails, shutdown fails, or aborts fail. If the Voice Video Session Manager does not fail to a secure state if system initialization fails, shutdown fails, or aborts fail, this is a finding.
Configure the Voice Video Session Manager to fail to a secure state if system initialization fails, shutdown fails, or aborts fail.
Verify that in the event of a system failure, the Voice Video Session Managers preserves any information necessary to determine cause of failure and any information necessary to return to operations with least disruption to mission processes. If the Voice Video Session Managers does not preserve all information necessary to determine cause of failure, this is a finding. If the Voice Video Session Managers does not preserve all information necessary to return to operations with least disruption to mission processes, this is a finding.
Configure the Voice Video Session Manager, in the event of a system failure, to preserve any information necessary to determine cause of failure and any information necessary to return to operations with least disruption to mission processes.
Verify the Voice Video Session Manager generates session records that provide information necessary for corrective actions without revealing personally identifiable information or sensitive information. If the Voice Video Session Manager does not generate session records that provide information necessary for corrective actions without revealing personally identifiable information or sensitive information, this is a finding.
Configure the Voice Video Session Manager to generate session records that provide information necessary for corrective actions without revealing personally identifiable information or sensitive information.
Verify the Voice Video Session Manager provides the capability to restrict Voice Video endpoint user access outside of operational hours to allow only essential connection capability. Areas requiring extended service times may be identified as exceptions. If the Voice Video Session Manager does not restrict Voice Video endpoint user access outside of operational hours allowing for exceptions, this is a finding.
Configure the Voice Video Session Manager to restrict Voice Video endpoint user access outside of operational hours to only essential connections.
Verify the Voice Video Session Manager immediately enforces change to privileges of Voice Video endpoint user access. Privileges include access to outside connections, precedence, and preemption capabilities. If the Voice Video Session Manager does not immediately enforce changes to privileges of Voice Video endpoint user access, this is a finding.
Configure the Voice Video Session Manager to immediately enforce changes to privileges of Voice Video endpoint user access.
Verify the Voice Video Session Manager immediately enforces change to privileges of Voice Video endpoint device access. Privileges include access to outside connections, precedence, and preemption capabilities. If the Voice Video Session Manager does not immediately enforce changes to privileges of Voice Video endpoint device access, this is a finding.
Configure the Voice Video Session Manager to immediately enforce changes to privileges of Voice Video endpoint device access.
Verify the Voice Video Session Manager provides centralized management of session records. Centralized management of session records may be a function of the Voice Video Session Manager or offloaded to an ancillary device. When records are offloaded, the Voice Video Session Manager must provide configuration settings to connect to the ancillary device. If the Voice Video Session Manager does not provide centralized management of session records, this is a finding.
Configure the Voice Video Session Manager to provide centralized management of session records.
Verify the Voice Video Session Manager off-loads session records onto a different system or storage media. If the Voice Video Session Manager does not off-load session records onto a different system or storage media, this is a finding.
Configure the Voice Video Session Manager to off-load session records onto a different system or storage media.
Verify the Voice Video Session Manager requires Voice Video endpoints to re-register at least every three hours. If the Voice Video Session Manager does not require Voice Video endpoints to re-register or does not enforce re-registration at least every three hours, this is a finding.
Configure the Voice Video Session Manager to re-register Voice Video endpoints at least every three hours.
Verify the Voice Video Session Manager requires Voice Video peers to re-register (re-authenticate) at least every hour. If the Voice Video Session Manager does not require Voice Video peers to re-register (re-authenticate) at least every hour, this is a finding.
Configure the Voice Video Session Manager to re-register (re-authenticate) Voice Video peers at least every hour.
Verify the Voice Video Session Manager authenticates all Voice Video endpoint devices before establishing any connection. If the Voice Video Session Manager does not authenticate all Voice Video endpoint devices before establishing any connection, this is a finding.
Configure the Voice Video Session Manager to authenticate all Voice Video endpoint devices before registering those devices.
Verify the Voice Video Session Manager authenticates all Voice Video peers (trunks) before establishing any connection. If the Voice Video Session Manager does not authenticate all Voice Video peers (trunks) before establishing any connection, this is a finding.
Configure the Voice Video Session Manager to authenticate all Voice Video peers (trunks) before registration.
Verify the Voice Video Session Manager provides an explicit indication of current participants in all videoconference-based and IP-based online meetings and conferences. This requirement does not apply to audio-only teleconferences using traditional telephony. If the Voice Video Session Manager does not provide an explicit indication of current participants in all videoconference-based and IP-based online meetings and conferences, this is a finding.
Configure the Voice Video Session Manager to provide an explicit indication of current participants in all videoconference-based and IP-based online meetings and conferences, except audio-only teleconferences using traditional telephony.
Verify the Voice Video Session Manager supporting C2 communications associates MLPP attributes when exchanged between UC system components. If the Voice Video Session Manager supporting C2 communications does not associate MLPP attributes when exchanged between UC system components, this is a finding.
Configure the Voice Video Session Manager supporting C2 communications to associate MLPP attributes when exchanged between UC system components.
Verify the Voice Video Session Manager supporting C2 communications limits and reserves bandwidth based on priority of the traffic type. If the Voice Video Session Manager supporting C2 communications does not limit and reserve bandwidth based on priority of the traffic type, this is a finding.
Configure the Voice Video Session Manager supporting C2 communications to limit and reserve bandwidth based on priority of the traffic type.
Verify the Voice Video Session Manager protects the confidentiality of transmitted configuration files, signaling, and media streams. If the Voice Video Session Manager does not protect the confidentiality of transmitted configuration files, signaling, and media streams, this is a finding.
Configure the Voice Video Session Manager to protect the confidentiality of transmitted configuration files, signaling, and media streams.
Verify the Voice Video Session Manager protects the integrity of transmitted configuration files, signaling, and media streams. If the Voice Video Session Manager does not protect the integrity of transmitted configuration files, signaling, and media streams, this is a finding.
Configure the Voice Video Session Manager to protect the integrity of transmitted configuration files, signaling, and media streams.
Verify the Voice Video Session Manager implements NIST FIPS-validated cryptography to generate cryptographic hashes and to protect sensitive unclassified information. If the Voice Video Session Manager does not implements NIST FIPS-validated cryptography to generate cryptographic hashes, this is a finding. If the Voice Video Session Manager does not implements NIST FIPS-validated cryptography to protect sensitive unclassified information, this is a finding.
Configure the Voice Video Session Manager to implement NIST FIPS-validated cryptography to generate cryptographic hashes and to protect sensitive unclassified information.
Verify the Voice Video Session Manager prohibits remote activation of collaborative computing devices. For centrally managed, dedicated videoconference suites located in approved videoconference locations with full documentation, this requirement is not applicable. If the Voice Video Session Manager does not prohibit remote activation of collaborative computing devices, this is a finding.
Configure the Voice Video Session Manager, except for centrally managed, dedicated videoconference suites located in approved videoconference locations, to prohibit remote activation of collaborative computing devices.
Verify the Voice Video Session Manager routes FES communications as a priority call in a non-blocking manner. If the Voice Video Session Manager does not route FES communications as a priority call in a non-blocking manner, this is a finding.
Configure the Voice Video Session Manager to route FES communications as a priority call in a non-blocking manner.
Verify the Voice Video Session Manager provides FES with the ANI of the initiator of the call. If the Voice Video Session Manager does not provide FES with the ANI of the initiator of the call, this is a finding.
Configure the Voice Video Session Manager to provide FES with the ANI of the initiator of the call.
Verify the Voice Video Session Manager provides FES with the ALI of the initiator of the call. If the Voice Video Session Manager does not provide FES with the ALI of the initiator of the call, this is a finding.
Configure the Voice Video Session Manager to provide FES with the ALI of the initiator of the call.
Verify the Voice Video Session Manager is configured in accordance with the security configuration settings based on DoD security configuration or implementation guidance, including STIGs, NSA configuration guides, CTOs, and DTMs. If the Voice Video Session Manager is not configured in accordance with the security configuration settings based on DoD security configuration or implementation guidance, including STIGs, NSA configuration guides, CTOs, and DTMs, this is a finding.
Configure the Voice Video Session Manager to be configured in accordance with the security configuration settings based on DoD security configuration or implementation guidance, including STIGs, NSA configuration guides, CTOs, and DTMs.
Verify the Voice Video Session Manager is configured to obfuscate passwords within configuration files. If the Voice Video Session Manager is not configured to obfuscate passwords within configuration files, this is a finding.
Configure the Voice Video Session Manager to obfuscate passwords within configuration files.
If the Voice Video Session Manager does not support voice video endpoints used for unclassified communication within a SCIF or SAPFs, this check procedure is Not Applicable. Verify the Voice Video Session Manager supporting voice video endpoints used for unclassified communication within a SCIF or SAPF is configured in accordance with the CNSSI 5000. If the Voice Video Session Manager is not configured in accordance with the CNSSI 5000, this is a finding.
Configure the Voice Video Session Manager supporting voice video endpoints used for unclassified communication within a SCIF or SAPF to be configured in accordance with CNSSI 5000.
Verify the Voice Video Session Manager applies 802.1Q VLAN tags to signaling and media traffic or be in a private subnet.. If the Voice Video Session Manager does not apply 802.1Q VLAN tags to signaling and media traffic or be in a private subnet., this is a finding.
Configure th Voice Video Session Manager to apply 802.1Q VLAN tags to signaling and media traffic or be in a private subnet.
Verify the Voice Video Session Manager uses a voice or video VLAN separate from all other VLANs. If the Voice Video Session Manager uses a voice or video VLAN that is not separate from all other VLANs, this is a finding.
Configure the Voice Video Session Manager to use a voice or video VLAN, separate from all other VLANs.