STIGQter STIGQter: STIG Summary: Enterprise Voice, Video, and Messaging Policy Security Requirements Guide Version: 1 Release: 4 Benchmark Date: 05 Jan 2026:

An inventory of authorized instruments must be documented and maintained in support of the detection of unauthorized instruments connected to the Enterprise Voice, Video, and Messaging system.

DISA Rule

SV-259903r1173929_rule

Vulnerability Number

V-259903

Group Title

SRG-VOIP-000230

Rule Version

SRG-VOIP-000230

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Ensure that an inventory of authorized instruments is documented and maintained.

NOTE: This inventory will be separate from the inventory created within the LSC from the listing of registered instruments. Authorized instruments must be added to this inventory before configuration in the LSC and instrument registration. The inventory may be offline or online on a separate server or workstation from the LSC (for example, the LSC management workstation).

Prepare and maintain an inventory/database of authorized VoIP instruments. Generate and store the inventory on a separate workstation or server from the LSC (for example, the LSC management workstation).

Recommendation: Create the inventory in a format that can easily be compared through automation to the report of registered instruments from the LSC (if available). This will facilitate regular review of the inventory to detect unauthorized instruments and will make the IA review easier.

Check Contents

Verify that an inventory of authorized instruments is documented and maintained.

Inspect the authorized instrument inventory.

NOTE: This inventory will be separate from the inventory created within the Local Session Controller (LSC) from the listing of registered instruments. Authorized instruments must be added to this inventory before configuration in the LSC and instrument registration. The inventory may be offline or online on a separate server or workstation from the LSC (for example, the LSC management workstation).

If the inventory does not exist or does not appear to be up to date, this is a finding.

Ask how this inventory is generated and where it is stored. If it is located on the LSC, this is a finding.

Vulnerability Number

V-259903

Documentable

False

Rule Version

SRG-VOIP-000230

Severity Override Guidance

Verify that an inventory of authorized instruments is documented and maintained.

Inspect the authorized instrument inventory.

NOTE: This inventory will be separate from the inventory created within the Local Session Controller (LSC) from the listing of registered instruments. Authorized instruments must be added to this inventory before configuration in the LSC and instrument registration. The inventory may be offline or online on a separate server or workstation from the LSC (for example, the LSC management workstation).

If the inventory does not exist or does not appear to be up to date, this is a finding.

Ask how this inventory is generated and where it is stored. If it is located on the LSC, this is a finding.

Check Content Reference

M

Target Key

5585