STIGQter STIGQter: STIG Summary: Enterprise Voice, Video, and Messaging Policy Security Requirements Guide Version: 1 Release: 4 Benchmark Date: 05 Jan 2026:

A site utilizing a commercial VoIP/SIP provider must use a provider compliant with FCC STIR/SHAKEN protocol rules.

DISA Rule

SV-274463r1107631_rule

Vulnerability Number

V-274463

Group Title

SRG-VOIP-000600

Rule Version

SRG-VOIP-000600

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Ensure the commercial provider is compliant with FCC STIR/SHAKEN regulations.

Check Contents

Verify the commercial provider is compliant with the FCC STIR/SHAKEN regulations.

If the commercial provider is not compliant with FCC STIR/SHAKEN regulations, this is a finding.

Vulnerability Number

V-274463

Documentable

False

Rule Version

SRG-VOIP-000600

Severity Override Guidance

Verify the commercial provider is compliant with the FCC STIR/SHAKEN regulations.

If the commercial provider is not compliant with FCC STIR/SHAKEN regulations, this is a finding.

Check Content Reference

M

Target Key

5585