STIGQter STIGQter: STIG Summary:

Enterprise Voice, Video, and Messaging Endpoint Security Requirements Guide

Version: 1

Release: 3 Benchmark Date: 01 Oct 2025

CheckedNameTitle
SV-259940r1117235_ruleThe Enterprise Voice, Video, and Messaging Endpoint must not be configured with any vendor default accounts, PINs, or passwords to access configuration settings.
SV-259941r1117235_ruleThe Enterprise Voice, Video, and Messaging Endpoint must be configured to prevent the configuration or display of configuration settings without the use of a PIN or password.
SV-259942r1117235_ruleThe Enterprise Voice, Video, and Messaging Endpoint must be configured to register with an Enterprise Voice, Video, and Messaging Session Manager.
SV-259943r1117236_ruleThe Enterprise Voice, Video, and Messaging Endpoint PC port must be configured to maintain VLAN separation from the voice video VLAN, or be disabled.
SV-259944r1117236_ruleThe Enterprise Voice, Video, and Messaging Endpoint must be configured to integrate into the implemented 802.1x network access control system.
SV-259945r1117236_ruleThe Enterprise Voice, Video, and Messaging Endpoint PC port must be configured to connect to an 802.1x supplicant or the PC port must be disabled.
SV-259946r1117236_ruleThe Enterprise Voice, Video, and Messaging Endpoint not supporting 802.1x must be configured to use MAC Authentication Bypass (MAB) on the access switchport.
SV-259947r1117236_ruleThe Enterprise Voice, Video, and Messaging Endpoint must be configured to use a voice video VLAN, separate from all other VLANs.
SV-259948r1132554_ruleThe Enterprise Voice, Video, and Messaging Endpoint must be configured to disable the Far End Camera Control feature if supported.
SV-259949r1117238_ruleThe Enterprise Voice, Video, and Messaging Endpoint must be configured to apply 802.1Q VLAN tags to signaling and media traffic.
SV-259950r948817_ruleThe Enterprise Voice, Video, and Messaging Endpoint must be configured to display the Standard Mandatory DOD Notice and Consent Banner before granting access to the network.
SV-259951r948820_ruleThe Enterprise Voice, Video, and Messaging Endpoint must be configured to retain the Standard Mandatory DOD Notice and Consent Banner on the screen until users acknowledge the usage conditions and take explicit actions to log on for further access.
SV-259952r987730_ruleThe Enterprise Voice, Video, and Messaging Endpoint must notify the user, upon successful logon (access) to the network element, of the date and time of the last logon (access).
SV-259953r987731_ruleThe Enterprise Voice, Video, and Messaging Endpoint must notify the user, upon successful logon (access), of the number of unsuccessful logon (access) attempts since the last successful logon (access).
SV-259954r948829_ruleThe Enterprise Voice, Video, and Messaging Endpoint must be configured to limit the number of concurrent sessions to an organizationally defined number.
SV-259955r948832_ruleThe Enterprise Voice, Video, and Messaging Endpoint must be configured to produce session (call detail) records containing what type of connection occurred.
SV-259956r948835_ruleThe Enterprise Voice, Video, and Messaging Endpoint must be configured to produce session (call detail) records containing when (date and time) the connection occurred.
SV-259957r948838_ruleThe Enterprise Voice, Video, and Messaging Endpoint must be configured to produce session (call detail) records containing where the connection occurred.
SV-259958r948841_ruleThe Enterprise Voice, Video, and Messaging Endpoint must be configured to produce session (call detail) records containing the source of the connection.
SV-259959r948844_ruleThe Enterprise Voice, Video, and Messaging Endpoint must be configured to produce session (call detail) records containing the outcome of the connection.
SV-259960r948847_ruleThe Enterprise Voice, Video, and Messaging Endpoint must be configured to produce session (call detail) records containing the identity of all users.
SV-259961r948850_ruleThe Enterprise Voice, Video, and Messaging Endpoint must be configured to provide session (call detail) record generation capability.
SV-259962r948853_ruleThe Enterprise Voice, Video, and Messaging Endpoint must be configured to disable or remove nonessential capabilities.
SV-259963r948856_ruleThe Enterprise Voice, Video, and Messaging Endpoint must be configured to only use ports, protocols, and services allowed per the Ports, Protocols, and Services Management (PPSM) Category Assurance List (CAL) and Vulnerability Assessments (VAs).
SV-259964r948859_ruleThe Enterprise Voice, Video, and Messaging Endpoint must be configured to uniquely identify participating users.
SV-259965r956067_ruleThe Enterprise Voice, Video, and Messaging Endpoint must use multifactor authentication for network access to nonprivileged (nonadmin) accounts.
SV-259966r1149317_ruleThe Enterprise Voice, Video, and Messaging Endpoint must be configured to implement replay-resistant authentication mechanisms for network access.
SV-259967r971530_ruleThe Enterprise Voice, Video, and Messaging Endpoint must be configured to terminate all network connections associated with a communications session at the end of the session.
SV-259968r948871_ruleThe Enterprise Voice, Video, and Messaging Endpoint must be configured to use FIPS-validated SHA-2 or higher to protect the authenticity of communications sessions.
SV-259969r948874_ruleIn the event of a device failure, Enterprise Voice, Video, and Messaging Endpoints must preserve any information necessary to determine cause of failure and return to operations with least disruption to service.
SV-259970r948877_ruleThe Enterprise Voice, Video, and Messaging Endpoint must offload audit records onto a different system or media than the system being audited.
SV-259971r1117244_ruleThe Enterprise Voice, Video, and Messaging Endpoint must be configured to use cryptographic algorithms approved by NSA to protect NSS when transporting classified traffic across an unclassified network.
SV-259972r987762_ruleThe Enterprise Voice, Video, and Messaging Endpoint must provide an explicit indication of current participants in all Videoconference (VC)-based and IP-based online meetings and conferences.
SV-259973r948886_ruleThe Enterprise Voice, Video, and Messaging Endpoint must be configured to use FIPS-compliant algorithms for network traffic.
SV-259974r948889_ruleThe Enterprise Voice, Video, and Messaging Endpoint, when using passwords or PINs for authentication or authorization, must be configured to cryptographically protect the PIN or password.
SV-259975r948892_ruleThe Enterprise Voice, Video, and Messaging Endpoint must generate audit records when successful/unsuccessful logon attempts occur.
SV-259976r948895_ruleThe Enterprise Voice, Video, and Messaging Endpoint must generate audit records for privileged activities or other system-level access.
SV-259977r948898_ruleThe Enterprise Voice, Video, and Messaging Endpoint must generate audit records showing starting and ending time for user access to the system.
SV-259978r948901_ruleThe Enterprise Voice, Video, and Messaging Endpoint must, at a minimum, offload interconnected systems in real-time and offload standalone systems weekly.
SV-259979r948904_ruleThe Enterprise Voice, Video, and Messaging Endpoint must be configured in accordance with the security configuration settings based on DOD security configuration or implementation guidance, including STIGs, NSA configuration guides, CTOs, and DTMs.
SV-259980r948907_ruleThe Enterprise Voice, Video, and Messaging Endpoint must be configured with a firmware release supported by the vendor.
SV-259981r948910_ruleThe Enterprise Voice, Video, and Messaging Endpoint must be configured to dynamically implement configuration file changes.
SV-259982r956073_ruleThe Enterprise Voice, Video, and Messaging Endpoint must be configured to disable any auto answer features.
SV-259983r948916_ruleThe Enterprise Voice, Video, and Messaging Endpoint must provide a logout capability for user-initiated communications sessions.
SV-259984r948919_ruleThe Enterprise Voice, Video, and Messaging Endpoint must display an explicit logout message to users indicating the reliable termination of communications sessions.
SV-259985r1149318_ruleFor accounts using password or PINs for authentication, the Enterprise Voice, Video, and Messaging Endpoint must store only cryptographic representations of passwords.
SV-259986r948925_ruleThe Enterprise Voice, Video, and Messaging Endpoint must prohibit client negotiation to TLS 1.1, TLS 1.0, SSL 2.0, or SSL 3.0.