STIGQter STIGQter: STIG Summary: Enterprise Voice, Video, and Messaging Policy Security Requirements Guide Version: 1 Release: 4 Benchmark Date: 05 Jan 2026:

Voice networks must not be bridged via a Unified Capability (UC) soft client accessory.

DISA Rule

SV-259905r1173931_rule

Vulnerability Number

V-259905

Group Title

SRG-VOIP-000250

Rule Version

SRG-VOIP-000250

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Discontinue the use of UC soft client accessories, including PPGs, ATAs, USB phones, and wireless headsets that provide a network bridging capability unless there is a validated and approved mission requirement for their use.

Check Contents

Determine if UC soft client accessories, including PPGs, ATAs, USB phones, and wireless headsets, that provide a network bridging capability to the PSTN are used on a DOD PC or network.

If so, further determine if there is a validated and approved mission requirement for their use. Interview a random sampling of users regarding their use of this bridging capability.

If these devices are used and there is no validated mission requirement, this is a finding.

NOTE: This requirement applies to Bluetooth, DECT/DECT 6.0, and other RF wireless technologies for accessories. Prior to procurement and implementation of any wireless accessory, a risk analysis must be performed to ensure the technology uses acceptable encryption and does not interfere with existing technology use. This guidance is not intended to replace the existing guidance available for wireless headsets used in association with mobile devices.

Vulnerability Number

V-259905

Documentable

False

Rule Version

SRG-VOIP-000250

Severity Override Guidance

Determine if UC soft client accessories, including PPGs, ATAs, USB phones, and wireless headsets, that provide a network bridging capability to the PSTN are used on a DOD PC or network.

If so, further determine if there is a validated and approved mission requirement for their use. Interview a random sampling of users regarding their use of this bridging capability.

If these devices are used and there is no validated mission requirement, this is a finding.

NOTE: This requirement applies to Bluetooth, DECT/DECT 6.0, and other RF wireless technologies for accessories. Prior to procurement and implementation of any wireless accessory, a risk analysis must be performed to ensure the technology uses acceptable encryption and does not interfere with existing technology use. This guidance is not intended to replace the existing guidance available for wireless headsets used in association with mobile devices.

Check Content Reference

M

Target Key

5585