STIGQter STIGQter: STIG Summary: Enterprise Voice, Video, and Messaging Policy Security Requirements Guide Version: 1 Release: 4 Benchmark Date: 05 Jan 2026:

Video conferencing, Unified Capability (UC) soft client, and speakerphone speaker operations policy must prevent disclosure of sensitive or classified information over nonsecure systems.

DISA Rule

SV-259902r1173873_rule

Vulnerability Number

V-259902

Group Title

SRG-VOIP-000220

Rule Version

SRG-VOIP-000220

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Document and enforce a policy and procedure for video conferencing, UC soft client, and speakerphone speaker operations to prevent disclosure of sensitive or classified information over nonsecure systems. Ensure appropriate training is provided for users.

The policy and supporting procedures should consider the classification of the area where the video conferencing equipment, the PC supporting a UC soft client, and Voice Video endpoints are placed, as well as the classification and need-to-know restraints of the information communicated within the area.

Include measures such as closing office or conference room doors, adjusting volume levels in open offices, and muting microphones when not directly in use.

Check Contents

Confirm a policy and supporting procedures are in place that address the placement and operation of video conferencing, UC soft client, and speakerphone speakers to prevent disclosure of sensitive or classified information over nonsecure systems. Operational policy and procedures must be included in user training and guides.

The policy and supporting procedures should consider the classification of the area where the video conferencing equipment, the PC supporting a UC soft client, and Voice Video endpoints are placed, as well as the classification and need-to-know restraints of the information communicated within the area.

They should include measures such as closing office or conference room doors, adjusting volume levels in open offices, and muting microphones when not directly in use.

If a policy and supporting procedures governing video conferencing, UC soft client, and speakerphone speaker operations preventing disclosure of sensitive or classified information over nonsecure systems do not exist or are not enforced, this is a finding.

Vulnerability Number

V-259902

Documentable

False

Rule Version

SRG-VOIP-000220

Severity Override Guidance

Confirm a policy and supporting procedures are in place that address the placement and operation of video conferencing, UC soft client, and speakerphone speakers to prevent disclosure of sensitive or classified information over nonsecure systems. Operational policy and procedures must be included in user training and guides.

The policy and supporting procedures should consider the classification of the area where the video conferencing equipment, the PC supporting a UC soft client, and Voice Video endpoints are placed, as well as the classification and need-to-know restraints of the information communicated within the area.

They should include measures such as closing office or conference room doors, adjusting volume levels in open offices, and muting microphones when not directly in use.

If a policy and supporting procedures governing video conferencing, UC soft client, and speakerphone speaker operations preventing disclosure of sensitive or classified information over nonsecure systems do not exist or are not enforced, this is a finding.

Check Content Reference

M

Target Key

5585