STIGQter STIGQter: STIG Summary: Enterprise Voice, Video, and Messaging Session Management Security Requirements Guide Version: 1 Release: 3 Benchmark Date: 01 Jul 2026:

The Enterprise Voice, Video, and Messaging Session Manager must automatically disable user accounts after a 35-day period of account inactivity.

DISA Rule

SV-259987r956074_rule

Vulnerability Number

V-259987

Group Title

SRG-NET-000004

Rule Version

SRG-NET-000004-VVSM-00101

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the Enterprise Voice, Video, and Messaging Session Manager to automatically disable Voice Video Endpoint user access after a 35-day period of account inactivity.

Check Contents

Verify the Enterprise Voice, Video, and Messaging Session Manager automatically disables Voice Video Endpoint user access after a 35-day period of account inactivity. This requirement refers to users rather than endpoints.

If the Enterprise Voice, Video, and Messaging Session Manager does not automatically disable Voice Video Endpoint user access after a 35-day period of account inactivity, this is a finding.

Vulnerability Number

V-259987

Documentable

False

Rule Version

SRG-NET-000004-VVSM-00101

Severity Override Guidance

Verify the Enterprise Voice, Video, and Messaging Session Manager automatically disables Voice Video Endpoint user access after a 35-day period of account inactivity. This requirement refers to users rather than endpoints.

If the Enterprise Voice, Video, and Messaging Session Manager does not automatically disable Voice Video Endpoint user access after a 35-day period of account inactivity, this is a finding.

Check Content Reference

M

Target Key

5587