STIGQter STIGQter: STIG Summary: Voice Video Services Policy Security Technical Implementation Guide Version: 3 Release: 17 Benchmark Date: 25 Oct 2019:

The LAN supporting VVoIP services must provide enhanced reliability, availability, and bandwidth.

DISA Rule

SV-21562r2_rule

Vulnerability Number

V-19500

Group Title

VVoIP 5100

Rule Version

VVoIP 5100

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

Implement and document the LAN supporting VVoIP services. VVoIP services must provide enhanced reliability, availability, and bandwidth. Voice bandwidth engineering is based on 102 kbps (each direction) for each IP call for IPv4 and 110.0 kbps for IPv6. Video bandwidth engineering is not so simple since when present, a single video stream can utilize 160kbps to 7.5Mbps in addition to any audio stream.

Check Contents

If the system does not support a minimum of 96 instruments, this requirement is not applicable. Review site documentation, network diagrams, and design information to confirm the LAN supporting VVoIP services provides enhanced reliability, availability, and bandwidth. Specific attention should be given in the areas of:
- Bandwidth and traffic engineering (25% voice, 25% video, 50% data)
- No single point of failure affecting service to greater than 96 instruments.
- Equipment reliability
- Equipment redundancy above the access layer
- Equipment robustness and bandwidth capability
- Connection redundancy above the access layer
- Connection bandwidth capability
- Access layer switch size (number of phones served)
- Backup power for all equipment

If the LAN supporting VVoIP services does not provide enhanced reliability, availability, and bandwidth or is deficient in these areas, this is a finding.

This check is not intended to initiate an in depth analysis of the network design. If the LAN is not is not properly designed it should be easily discerned because many of the criteria will not be met unless the LAN was already designed for high reliability and availability before adding VVoIP services.

Vulnerability Number

V-19500

Documentable

False

Rule Version

VVoIP 5100

Severity Override Guidance

If the system does not support a minimum of 96 instruments, this requirement is not applicable. Review site documentation, network diagrams, and design information to confirm the LAN supporting VVoIP services provides enhanced reliability, availability, and bandwidth. Specific attention should be given in the areas of:
- Bandwidth and traffic engineering (25% voice, 25% video, 50% data)
- No single point of failure affecting service to greater than 96 instruments.
- Equipment reliability
- Equipment redundancy above the access layer
- Equipment robustness and bandwidth capability
- Connection redundancy above the access layer
- Connection bandwidth capability
- Access layer switch size (number of phones served)
- Backup power for all equipment

If the LAN supporting VVoIP services does not provide enhanced reliability, availability, and bandwidth or is deficient in these areas, this is a finding.

This check is not intended to initiate an in depth analysis of the network design. If the LAN is not is not properly designed it should be easily discerned because many of the criteria will not be met unless the LAN was already designed for high reliability and availability before adding VVoIP services.

Check Content Reference

M

Target Key

594

Comments