STIGQter STIGQter: STIG Summary: Video Services Policy STIG Version: 1 Release: 11 Benchmark Date: 24 Apr 2020:

User Guides and documentation packages must be developed and distributed to users operating VTC endpoints.

DISA Rule

SV-18886r2_rule

Vulnerability Number

V-17712

Group Title

RTS-VTC 3740

Rule Version

RTS-VTC 3740.00

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Implement a policy or procedure for User Guides and documentation packages to be developed and distributed to users operating VTC endpoints, to include conference room systems that provide the following information:
- Reiterates the policies and restrictions agreed to when the user’s agreement was signed upon receiving the VTC endpoint of authorization to use one.
- Provides cautions and notice of the non-assured nature of VTC communications so that C2 users are aware and reminded regarding the use of this communications media for C2.
- Provides instruction regarding the proper and safe use of a VTC endpoint’s or conference room system’s audio and video capabilities such that the appropriate confidentiality of meeting related and non-meeting related information is maintained.
- Provides instruction regarding the proper and safe use of document and desktop sharing when using a PC connected to a VTC endpoint such that the appropriate confidentiality of meeting related and non-meeting related information is maintained.
- Provides instruction regarding the safeguarding of meeting related and non-meeting related sensitive and/or classified information.

Check Contents

Review site documentation to confirm user guides and documentation packages are developed and distributed to users operating VTC endpoints, to include conference room systems, that provides the following information:
- Reiterates the policies and restrictions agreed to when the user’s agreement was signed upon receiving the VTC endpoint of authorization to use one.
- Provides cautions and notice of the non-assured nature of VTC communications so that C2 users are aware and reminded regarding the use of this communications media for C2.
- Provides instruction regarding the proper and safe use of a VTC endpoint’s or conference room system’s audio and video capabilities such that the appropriate confidentiality of meeting related and non-meeting related information is maintained.
- Provides instruction regarding the proper and safe use of document and desktop sharing when using a PC connected to a VTC endpoint such that the appropriate confidentiality of meeting related and non-meeting related information is maintained.
- Provides instruction regarding the safeguarding of meeting related and non-meeting related sensitive and/or classified information

If user guides and documentation packages are not developed and distributed to users operating VTC endpoints, this is a finding.

Vulnerability Number

V-17712

Documentable

False

Rule Version

RTS-VTC 3740.00

Severity Override Guidance

Review site documentation to confirm user guides and documentation packages are developed and distributed to users operating VTC endpoints, to include conference room systems, that provides the following information:
- Reiterates the policies and restrictions agreed to when the user’s agreement was signed upon receiving the VTC endpoint of authorization to use one.
- Provides cautions and notice of the non-assured nature of VTC communications so that C2 users are aware and reminded regarding the use of this communications media for C2.
- Provides instruction regarding the proper and safe use of a VTC endpoint’s or conference room system’s audio and video capabilities such that the appropriate confidentiality of meeting related and non-meeting related information is maintained.
- Provides instruction regarding the proper and safe use of document and desktop sharing when using a PC connected to a VTC endpoint such that the appropriate confidentiality of meeting related and non-meeting related information is maintained.
- Provides instruction regarding the safeguarding of meeting related and non-meeting related sensitive and/or classified information

If user guides and documentation packages are not developed and distributed to users operating VTC endpoints, this is a finding.

Check Content Reference

M

Responsibility

Other

Target Key

1418

Comments