STIGQter STIGQter: STIG Summary: Enterprise Voice, Video, and Messaging Session Management Security Requirements Guide Version: 1 Release: 3 Benchmark Date: 01 Jul 2026:

The Enterprise Voice, Video, and Messaging Session Manager must be configured to only enable the extension mobility feature for endpoints on a per user basis.

DISA Rule

SV-259989r1117236_rule

Vulnerability Number

V-259989

Group Title

SRG-NET-000018

Rule Version

SRG-NET-000018-VVSM-00101

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the extension mobility feature only when enabled per user. Confirm the following specific security features are configured:
- The feature is enabled/disabled on a per user basis.
- Feature activation requires user authentication minimally using a user unique PIN (preferably including a unique user ID).
- Feature is not activated using a common activation code, or feature button on the phone.
- The user (or system administrator) can manually disable the feature at their discretion.
- The user may have the capability to set duration when activating the feature. (Optional)
- The feature automatically deactivates based on a period of inactivity or the time of day.

Check Contents

Verify the configuration for the extension mobility feature is only available when enabled per user. Confirm the following specific security features are configured:
- The feature is enabled/disabled on a per user basis.
- Feature activation requires user authentication minimally using a user unique PIN (preferably including a unique user ID).
- Feature is not activated using a common activation code, or feature button on the phone.
- The user (or system administrator) can manually disable the feature at their discretion.
- The user may have the capability to set duration when activating the feature. (Optional)
- The feature automatically deactivates based on a period of inactivity or the time of day.

If the extension mobility feature is enabled and does not meet the above specific security features, this is a finding.

Vulnerability Number

V-259989

Documentable

False

Rule Version

SRG-NET-000018-VVSM-00101

Severity Override Guidance

Verify the configuration for the extension mobility feature is only available when enabled per user. Confirm the following specific security features are configured:
- The feature is enabled/disabled on a per user basis.
- Feature activation requires user authentication minimally using a user unique PIN (preferably including a unique user ID).
- Feature is not activated using a common activation code, or feature button on the phone.
- The user (or system administrator) can manually disable the feature at their discretion.
- The user may have the capability to set duration when activating the feature. (Optional)
- The feature automatically deactivates based on a period of inactivity or the time of day.

If the extension mobility feature is enabled and does not meet the above specific security features, this is a finding.

Check Content Reference

M

Target Key

5587