STIGQter STIGQter: STIG Summary: Enterprise Voice, Video, and Messaging Endpoint Security Requirements Guide Version: 1 Release: 3 Benchmark Date: 01 Oct 2025:

The Enterprise Voice, Video, and Messaging Endpoint must be configured to produce session (call detail) records containing what type of connection occurred.

DISA Rule

SV-259955r948832_rule

Vulnerability Number

V-259955

Group Title

SRG-NET-000074

Rule Version

SRG-NET-000074-VVEP-00022

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the Enterprise Voice, Video, and Messaging Endpoint to produce session records containing what type of connection occurred.

Check Contents

Verify the Enterprise Voice, Video, and Messaging Endpoint produces session records containing what type of connection occurred. The record must include the session type (voice/direct, voice/conference, video/direct, video/conference, etc.), the specific protocols used for control and media traffic (SIP/SRTP, H.323, etc.), and the type of endpoint (mobile, telephone, codec, etc.).

If the Enterprise Voice, Video, and Messaging Endpoint does not produce session records containing what type of connection occurred, this is a finding.

Vulnerability Number

V-259955

Documentable

False

Rule Version

SRG-NET-000074-VVEP-00022

Severity Override Guidance

Verify the Enterprise Voice, Video, and Messaging Endpoint produces session records containing what type of connection occurred. The record must include the session type (voice/direct, voice/conference, video/direct, video/conference, etc.), the specific protocols used for control and media traffic (SIP/SRTP, H.323, etc.), and the type of endpoint (mobile, telephone, codec, etc.).

If the Enterprise Voice, Video, and Messaging Endpoint does not produce session records containing what type of connection occurred, this is a finding.

Check Content Reference

M

Target Key

5586