STIGQter STIGQter: STIG Summary: Voice Video Services Policy Security Technical Implementation Guide Version: 3 Release: 17 Benchmark Date: 25 Oct 2019:

Implementing Unified Capabilities (UC) soft clients as the primary voice endpoint must have Authorizing Official (AO) approval.

DISA Rule

SV-17083r2_rule

Vulnerability Number

V-16095

Group Title

VVoIP 1110

Rule Version

VVoIP 1110

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Obtain the Command and AO approval for the implementation or transition to UC soft clients as the primary endpoints in writing. Approval documentation must be maintained by the ISSO for future inspection by IA reviewers or auditors. If Command and AO written approval is not available, hardware endpoints must be used as the primary endpoints.

Note: This requirement is in addition to AO approval for deploying UC soft clients on DoD networks (VVoIP 1720). When UC soft clients are deployed as the primary endpoint, additional risks to availability exist.

Check Contents

Ensure the Command and AO approves the implementation or transition to UC soft clients as the primary endpoints in writing. Approval documentation will be maintained by the ISSO for inspection by IA reviewers or auditors.

Review the written Command and AO approval for the implementation of a telephone system which primarily uses UC soft client applications for its endpoints.

If no written Command and AO approval exist for UC soft client endpoints, this is a finding.

Vulnerability Number

V-16095

Documentable

False

Rule Version

VVoIP 1110

Severity Override Guidance

Ensure the Command and AO approves the implementation or transition to UC soft clients as the primary endpoints in writing. Approval documentation will be maintained by the ISSO for inspection by IA reviewers or auditors.

Review the written Command and AO approval for the implementation of a telephone system which primarily uses UC soft client applications for its endpoints.

If no written Command and AO approval exist for UC soft client endpoints, this is a finding.

Check Content Reference

M

Responsibility

Information Assurance Manager

Target Key

594

Comments