STIGQter STIGQter: STIG Summary: Enterprise Voice, Video, and Messaging Policy Security Requirements Guide Version: 1 Release: 4 Benchmark Date: 05 Jan 2026:

The Enterprise Voice, Video, and Messaging Policy must define operations for VTC and endpoint cameras regarding the ability to pick up and transmit sensitive information.

DISA Rule

SV-259890r1173861_rule

Vulnerability Number

V-259890

Group Title

SRG-VOIP-000100

Rule Version

SRG-VOIP-000100

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Ensure a policy and procedure is in place and enforced that addresses the operation of video/collaboration communications-related cameras (e.g., webcams or VTC cameras) regarding their ability to inadvertently capture and transmit sensitive or classified information.

Do not post potentially sensitive information on the walls in view of the camera(s).

Produce an SOP that addresses the operation of video/collaboration communications-related cameras (e.g., webcams or VTC cameras) regarding their ability to inadvertently capture and transmit sensitive or classified information such that:
- Conference room and office users do not display sensitive or classified information on walls that are within the view of the camera(s).
- Conference room and office users do not place sensitive or classified information on a table or desk within the view of the camera(s) without proper protection. (e.g., a proper cover).
- Conference room and office users do not read or view sensitive or classified information at such an angle that the camera(s) could focus on it.

NOTE: While covering such information mitigates disclosure when a camera is to be used, if the camera is activated unexpectedly or without taking action to cover the information prior to activating, the information can be compromised. Best practice is to not display it in view of the camera at all.

Provide appropriate training so users follow the SOP. Enforce user compliance with the SOP.

Check Contents

Verify a policy and procedure is in place and enforced that addresses the operation of video/collaboration communications-related cameras (e.g., webcams or VTC cameras) regarding their ability to inadvertently capture and transmit sensitive or classified information such that:
- Conference room and office users do not display sensitive or classified information on walls that are within the view of the camera(s).
- Conference room and office users do not place sensitive or classified information on a table or desk within the view of the camera(s) without proper protection (e.g., a proper cover).
- Conference room and office users do not read or view sensitive or classified information at such an angle that the camera(s) could focus on it.

NOTE: While covering such information mitigates disclosure when a camera is to be used, if the camera is activated unexpectedly or without taking action to cover the information prior to activating, the information can be compromised. The best practice is to not display it in view of the camera at all.

Inspect the applicable standard operating procedure (SOP).

Inspect a random sampling of workspaces and conference rooms to determine compliance. Look for potentially sensitive information posted on the walls in view of the camera(s).

Interview the ISSO to determine how the SOP is enforced. Inspect user training materials and discuss practices to determine if information regarding the SOP is conveyed. Interview a random sampling of users to confirm their awareness of the SOP and related information.

If deficiencies are found in any of these areas, this is a finding. Note the deficiencies in the finding details.

Vulnerability Number

V-259890

Documentable

False

Rule Version

SRG-VOIP-000100

Severity Override Guidance

Verify a policy and procedure is in place and enforced that addresses the operation of video/collaboration communications-related cameras (e.g., webcams or VTC cameras) regarding their ability to inadvertently capture and transmit sensitive or classified information such that:
- Conference room and office users do not display sensitive or classified information on walls that are within the view of the camera(s).
- Conference room and office users do not place sensitive or classified information on a table or desk within the view of the camera(s) without proper protection (e.g., a proper cover).
- Conference room and office users do not read or view sensitive or classified information at such an angle that the camera(s) could focus on it.

NOTE: While covering such information mitigates disclosure when a camera is to be used, if the camera is activated unexpectedly or without taking action to cover the information prior to activating, the information can be compromised. The best practice is to not display it in view of the camera at all.

Inspect the applicable standard operating procedure (SOP).

Inspect a random sampling of workspaces and conference rooms to determine compliance. Look for potentially sensitive information posted on the walls in view of the camera(s).

Interview the ISSO to determine how the SOP is enforced. Inspect user training materials and discuss practices to determine if information regarding the SOP is conveyed. Interview a random sampling of users to confirm their awareness of the SOP and related information.

If deficiencies are found in any of these areas, this is a finding. Note the deficiencies in the finding details.

Check Content Reference

M

Target Key

5585