STIGQter STIGQter: STIG Summary:

Enterprise Voice, Video, and Messaging Session Management Security Requirements Guide

Version: 1

Release: 3 Benchmark Date: 01 Jul 2026

CheckedNameTitle
SV-259987r956074_ruleThe Enterprise Voice, Video, and Messaging Session Manager must automatically disable user accounts after a 35-day period of account inactivity.
SV-259988r1117235_ruleThe Enterprise Voice, Video, and Messaging Session Manager must disable (prevent) auto-registration of Voice Video Endpoints.
SV-259989r1117236_ruleThe Enterprise Voice, Video, and Messaging Session Manager must be configured to only enable the extension mobility feature for endpoints on a per user basis.
SV-259990r1117236_ruleThe Enterprise Voice, Video, and Messaging Session Manager must be configured to globally disable the extension mobility feature for endpoints.
SV-259991r1117236_ruleThe Enterprise Voice, Video, and Messaging Session Manager must be configured to use DNS servers assigned to support the VVoIP system.
SV-259992r1173942_ruleThe Enterprise Voice, Video, and Messaging Session Manager must display the Standard Mandatory DOD Notice and Consent Banner before granting access to management sessions.
SV-259993r1173943_ruleThe Enterprise Voice, Video, and Messaging Session Manager must retain the Standard Mandatory DOD Notice and Consent Banner on the screen for management sessions until admins acknowledge the usage conditions and take explicit actions to log on for further access.
SV-259994r948943_ruleThe Enterprise Voice, Video, and Messaging Session Manager must limit the number of concurrent management sessions to an organizationally defined limit.
SV-259995r948946_ruleThe Enterprise Voice, Video, and Messaging Session Manager must use TLS 1.2 or greater to protect the confidentiality of remote access.
SV-259996r948949_ruleThe Enterprise Voice, Video, and Messaging Session Manager must produce session (call) records containing the type of session connection.
SV-259997r948952_ruleThe Enterprise Voice, Video, and Messaging Session Manager must produce session (call) records containing timestamps (date and time) for all session connections.
SV-259998r948955_ruleThe Enterprise Voice, Video, and Messaging Session Manager must produce session (call) records containing where (location) the connection originated.
SV-259999r948958_ruleThe Enterprise Voice, Video, and Messaging Session Manager must produce session (call) records containing the identity of the initiator of the call.
SV-260000r948961_ruleThe Enterprise Voice, Video, and Messaging Session Manager must produce session (call) records containing the outcome (status) of the connection.
SV-260001r948964_ruleThe Enterprise Voice, Video, and Messaging Session Manager must produce session (call) records containing the identity of the users and identifiers associated with the session.
SV-260002r948967_ruleThe Enterprise Voice, Video, and Messaging Session Manager must alert the information system security officer (ISSO) and system administrator (SA) (at a minimum) in the event of a session (call) record system failure.
SV-260003r948970_ruleThe Enterprise Voice, Video, and Messaging Session Manager must protect session (call) records from unauthorized read access.
SV-260004r948973_ruleThe Enterprise Voice, Video, and Messaging Session Manager must protect session (call) records from unauthorized modification.
SV-260005r948976_ruleThe Enterprise Voice, Video, and Messaging Session Manager must protect session (call) records from unauthorized deletion.
SV-260006r948979_ruleThe Enterprise Voice, Video, and Messaging Session Manager must produce session (call) records for events determined to be significant and relevant by local policy.
SV-260007r948982_ruleThe Enterprise Voice, Video, and Messaging Session Manager must be configured to disable nonessential capabilities.
SV-260008r948985_ruleThe Enterprise Voice, Video, and Messaging Session Manager must only use ports, protocols, and services allowed per the Ports, Protocols, and Services Management (PPSM) Category Assurance List (CAL) and Vulnerability Assessments (VAs).
SV-260009r948988_ruleThe Enterprise Voice, Video, and Messaging Session Manager must be configured to uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users).
SV-260010r948991_ruleThe Enterprise Voice, Video, and Messaging Session Manager must be configured to use an organizational-level user account management system.
SV-260011r1173877_ruleThe Enterprise Voice, Video, and Messaging Session Manager must be configured to implement attack-resistant mechanisms for Voice Video Endpoint registration.
SV-260012r948997_ruleThe Enterprise Voice, Video, and Messaging Session Manager must be configured to uniquely identify each Voice Video Endpoint device before registration.
SV-260013r971530_ruleThe Enterprise Voice, Video, and Messaging Session Manager must be configured to terminate all network connections associated with a communications session at the end of the session.
SV-260014r949003_ruleThe Enterprise Voice, Video, and Messaging Session Manager supporting Command and Control (C2) communications must associate multilevel precedence and preemption (MLPP) attributes when exchanged between unified capabilities (UC) systems.
SV-260015r1117232_ruleThe Enterprise Voice, Video, and Messaging Session Manager supporting Command and Control (C2) communications must validate the integrity of transmitted multilevel precedence and preemption (MLPP) attributes.
SV-260016r949009_ruleThe Enterprise Voice, Video, and Messaging Session Manager must be configured to use FIPS-validated SHA-2 or higher to protect the authenticity of communications sessions.
SV-260017r949012_ruleThe Enterprise Voice, Video, and Messaging Session Manager must fail to a secure state if system initialization fails, shutdown fails, or aborts fail.
SV-260018r949015_ruleIn the event of a system failure, Enterprise Voice, Video, and Messaging Session Managers must be configured to preserve any information necessary to determine cause of failure and any information necessary to return to operations with least disruption to mission processes.
SV-260019r949018_ruleThe Enterprise Voice, Video, and Messaging Session Manager must be configured to generate session (call) records that provide information necessary for corrective actions without revealing personally identifiable information or sensitive information.
SV-260020r949021_ruleThe Enterprise Voice, Video, and Messaging Session Manager must be configured to restrict Enterprise Voice, Video, and Messaging Session Manager access outside of operational hours.
SV-260021r987749_ruleThe Enterprise Voice, Video, and Messaging Session Manager must be configured to enforce changes to privileges of Voice Video Endpoint user access.
SV-260022r987750_ruleThe Enterprise Voice, Video, and Messaging Session Manager must be configured to enforce changes to privileges of Voice Video Endpoint device access.
SV-260024r949033_ruleThe Enterprise Voice, Video, and Messaging Session Manager must be configured to offload session (call) records to a central log server.
SV-260025r1173880_ruleThe Enterprise Voice, Video, and Messaging Session Manager must be configured to require Voice Video Endpoints to re-register at least every three hours.
SV-260026r1173881_ruleThe Enterprise Voice, Video, and Messaging Session Manager must be configured to require Voice Video peers to re-register (reauthenticate) at least every hour.
SV-260027r949042_ruleThe Enterprise Voice, Video, and Messaging Session Manager must be configured to authenticate each Voice Video Endpoint device before registration.
SV-260028r949045_ruleThe Enterprise Voice, Video, and Messaging Session Manager must be configured to authenticate each Voice Video peer (trunk) before registration.
SV-260029r987762_ruleThe Enterprise Voice, Video, and Messaging Session Manager must be configured to provide an indication of current participants in all calls, meetings, and conferences.
SV-260030r949051_ruleThe Enterprise Voice, Video, and Messaging Session Manager supporting Command and Control (C2) communications must associate multilevel precedence and preemption (MLPP) attributes when exchanged between unified capabilities (UC) system components.
SV-260031r956076_ruleThe Enterprise Voice, Video, and Messaging Session Manager must only allow the use of DOD-approved PKI certificate authorities when using PKI.
SV-260032r949057_ruleThe Enterprise Voice, Video, and Messaging Session Manager must be configured to protect against or limit the effects of all types of denial-of-service (DoS) attacks by employing organizationally defined security safeguards.
SV-260033r987769_ruleThe Enterprise Voice, Video, and Messaging Session Manager must be configured to limit and reserve bandwidth based on priority of the traffic type.
SV-260034r949063_ruleThe Enterprise Voice, Video, and Messaging Session Manager must be configured to protect the confidentiality and integrity of transmitted configuration files, signaling, and media streams.
SV-260035r949066_ruleThe Enterprise Voice, Video, and Messaging Session Manager, when using locally stored user accounts, must automatically lock the account until the locked account is released by an administrator when three unsuccessful logon attempts in 15 minutes are exceeded.
SV-260036r1207650_ruleFor accounts using password authentication, the Enterprise Voice, Video, and Messaging Session Manager must be configured to use FIPS-validated SHA-2 or later protocol to protect the integrity of the password authentication process.
SV-260037r949072_ruleThe Enterprise Voice, Video, and Messaging Session Manager must generate session (call) records when concurrent logons from multiple endpoints occur.
SV-260038r949075_ruleWhen using locally stored user accounts, the Enterprise Voice, Video, and Messaging Session Manager must generate audit records for all account creations, modifications, disabling, and termination events.
SV-260039r1117247_ruleThe Enterprise Voice, Video, and Messaging Session Manager must implement NIST FIPS-validated cryptography for communications sessions.
SV-260040r949081_ruleThe Enterprise Voice, Video, and Messaging Session Manager must be configured to use the organization authoritative time source (NTP) to maintain system time.
SV-260041r949084_ruleThe Enterprise Voice, Video, and Messaging Session Manager must be configured in accordance with the security configuration settings based on DOD security configuration or implementation guidance, including STIGs, NSA configuration guides, CTOs, and DTMs.
SV-260042r949087_ruleThe Enterprise Voice, Video, and Messaging Session Manager requiring user access authentication must provide a logout capability for user-initiated communications sessions.
SV-260043r1117223_ruleThe Enterprise Voice, Video, and Messaging Session Manager must be configured to apply 802.1Q VLAN tags to signaling and media traffic.
SV-260044r1117223_ruleThe Enterprise Voice, Video, and Messaging Session Manager must be configured to use a voice or video VLAN, separate from all other VLANs.
SV-260045r1173878_ruleWhen using locally stored user accounts, the Enterprise Voice, Video, and Messaging Session Manager must store only cryptographic representations of passwords.
SV-260046r949099_ruleThe Enterprise Voice, Video, and Messaging Session Manager must be configured to use only TLS 1.2 or greater for all TLS and SSL communications.
SV-260047r949102_ruleWhen using PKI, the Enterprise Voice, Video, and Messaging Session Manager must validate certificates used for Transport Layer Security (TLS) functions by performing RFC 5280-compliant certification path validation.