| Checked | Name | Title |
|---|
| ☐ | SV-259987r956074_rule | The Enterprise Voice, Video, and Messaging Session Manager must automatically disable user accounts after a 35-day period of account inactivity. |
| ☐ | SV-259988r1117235_rule | The Enterprise Voice, Video, and Messaging Session Manager must disable (prevent) auto-registration of Voice Video Endpoints. |
| ☐ | SV-259989r1117236_rule | The Enterprise Voice, Video, and Messaging Session Manager must be configured to only enable the extension mobility feature for endpoints on a per user basis. |
| ☐ | SV-259990r1117236_rule | The Enterprise Voice, Video, and Messaging Session Manager must be configured to globally disable the extension mobility feature for endpoints. |
| ☐ | SV-259991r1117236_rule | The Enterprise Voice, Video, and Messaging Session Manager must be configured to use DNS servers assigned to support the VVoIP system. |
| ☐ | SV-259992r1173942_rule | The Enterprise Voice, Video, and Messaging Session Manager must display the Standard Mandatory DOD Notice and Consent Banner before granting access to management sessions. |
| ☐ | SV-259993r1173943_rule | The Enterprise Voice, Video, and Messaging Session Manager must retain the Standard Mandatory DOD Notice and Consent Banner on the screen for management sessions until admins acknowledge the usage conditions and take explicit actions to log on for further access. |
| ☐ | SV-259994r948943_rule | The Enterprise Voice, Video, and Messaging Session Manager must limit the number of concurrent management sessions to an organizationally defined limit. |
| ☐ | SV-259995r948946_rule | The Enterprise Voice, Video, and Messaging Session Manager must use TLS 1.2 or greater to protect the confidentiality of remote access. |
| ☐ | SV-259996r948949_rule | The Enterprise Voice, Video, and Messaging Session Manager must produce session (call) records containing the type of session connection. |
| ☐ | SV-259997r948952_rule | The Enterprise Voice, Video, and Messaging Session Manager must produce session (call) records containing timestamps (date and time) for all session connections. |
| ☐ | SV-259998r948955_rule | The Enterprise Voice, Video, and Messaging Session Manager must produce session (call) records containing where (location) the connection originated. |
| ☐ | SV-259999r948958_rule | The Enterprise Voice, Video, and Messaging Session Manager must produce session (call) records containing the identity of the initiator of the call. |
| ☐ | SV-260000r948961_rule | The Enterprise Voice, Video, and Messaging Session Manager must produce session (call) records containing the outcome (status) of the connection. |
| ☐ | SV-260001r948964_rule | The Enterprise Voice, Video, and Messaging Session Manager must produce session (call) records containing the identity of the users and identifiers associated with the session. |
| ☐ | SV-260002r948967_rule | The Enterprise Voice, Video, and Messaging Session Manager must alert the information system security officer (ISSO) and system administrator (SA) (at a minimum) in the event of a session (call) record system failure. |
| ☐ | SV-260003r948970_rule | The Enterprise Voice, Video, and Messaging Session Manager must protect session (call) records from unauthorized read access. |
| ☐ | SV-260004r948973_rule | The Enterprise Voice, Video, and Messaging Session Manager must protect session (call) records from unauthorized modification. |
| ☐ | SV-260005r948976_rule | The Enterprise Voice, Video, and Messaging Session Manager must protect session (call) records from unauthorized deletion. |
| ☐ | SV-260006r948979_rule | The Enterprise Voice, Video, and Messaging Session Manager must produce session (call) records for events determined to be significant and relevant by local policy. |
| ☐ | SV-260007r948982_rule | The Enterprise Voice, Video, and Messaging Session Manager must be configured to disable nonessential capabilities. |
| ☐ | SV-260008r948985_rule | The Enterprise Voice, Video, and Messaging Session Manager must only use ports, protocols, and services allowed per the Ports, Protocols, and Services Management (PPSM) Category Assurance List (CAL) and Vulnerability Assessments (VAs). |
| ☐ | SV-260009r948988_rule | The Enterprise Voice, Video, and Messaging Session Manager must be configured to uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users). |
| ☐ | SV-260010r948991_rule | The Enterprise Voice, Video, and Messaging Session Manager must be configured to use an organizational-level user account management system. |
| ☐ | SV-260011r1173877_rule | The Enterprise Voice, Video, and Messaging Session Manager must be configured to implement attack-resistant mechanisms for Voice Video Endpoint registration. |
| ☐ | SV-260012r948997_rule | The Enterprise Voice, Video, and Messaging Session Manager must be configured to uniquely identify each Voice Video Endpoint device before registration. |
| ☐ | SV-260013r971530_rule | The Enterprise Voice, Video, and Messaging Session Manager must be configured to terminate all network connections associated with a communications session at the end of the session. |
| ☐ | SV-260014r949003_rule | The Enterprise Voice, Video, and Messaging Session Manager supporting Command and Control (C2) communications must associate multilevel precedence and preemption (MLPP) attributes when exchanged between unified capabilities (UC) systems. |
| ☐ | SV-260015r1117232_rule | The Enterprise Voice, Video, and Messaging Session Manager supporting Command and Control (C2) communications must validate the integrity of transmitted multilevel precedence and preemption (MLPP) attributes. |
| ☐ | SV-260016r949009_rule | The Enterprise Voice, Video, and Messaging Session Manager must be configured to use FIPS-validated SHA-2 or higher to protect the authenticity of communications sessions. |
| ☐ | SV-260017r949012_rule | The Enterprise Voice, Video, and Messaging Session Manager must fail to a secure state if system initialization fails, shutdown fails, or aborts fail. |
| ☐ | SV-260018r949015_rule | In the event of a system failure, Enterprise Voice, Video, and Messaging Session Managers must be configured to preserve any information necessary to determine cause of failure and any information necessary to return to operations with least disruption to mission processes. |
| ☐ | SV-260019r949018_rule | The Enterprise Voice, Video, and Messaging Session Manager must be configured to generate session (call) records that provide information necessary for corrective actions without revealing personally identifiable information or sensitive information. |
| ☐ | SV-260020r949021_rule | The Enterprise Voice, Video, and Messaging Session Manager must be configured to restrict Enterprise Voice, Video, and Messaging Session Manager access outside of operational hours. |
| ☐ | SV-260021r987749_rule | The Enterprise Voice, Video, and Messaging Session Manager must be configured to enforce changes to privileges of Voice Video Endpoint user access. |
| ☐ | SV-260022r987750_rule | The Enterprise Voice, Video, and Messaging Session Manager must be configured to enforce changes to privileges of Voice Video Endpoint device access. |
| ☐ | SV-260024r949033_rule | The Enterprise Voice, Video, and Messaging Session Manager must be configured to offload session (call) records to a central log server. |
| ☐ | SV-260025r1173880_rule | The Enterprise Voice, Video, and Messaging Session Manager must be configured to require Voice Video Endpoints to re-register at least every three hours. |
| ☐ | SV-260026r1173881_rule | The Enterprise Voice, Video, and Messaging Session Manager must be configured to require Voice Video peers to re-register (reauthenticate) at least every hour. |
| ☐ | SV-260027r949042_rule | The Enterprise Voice, Video, and Messaging Session Manager must be configured to authenticate each Voice Video Endpoint device before registration. |
| ☐ | SV-260028r949045_rule | The Enterprise Voice, Video, and Messaging Session Manager must be configured to authenticate each Voice Video peer (trunk) before registration. |
| ☐ | SV-260029r987762_rule | The Enterprise Voice, Video, and Messaging Session Manager must be configured to provide an indication of current participants in all calls, meetings, and conferences. |
| ☐ | SV-260030r949051_rule | The Enterprise Voice, Video, and Messaging Session Manager supporting Command and Control (C2) communications must associate multilevel precedence and preemption (MLPP) attributes when exchanged between unified capabilities (UC) system components. |
| ☐ | SV-260031r956076_rule | The Enterprise Voice, Video, and Messaging Session Manager must only allow the use of DOD-approved PKI certificate authorities when using PKI. |
| ☐ | SV-260032r949057_rule | The Enterprise Voice, Video, and Messaging Session Manager must be configured to protect against or limit the effects of all types of denial-of-service (DoS) attacks by employing organizationally defined security safeguards. |
| ☐ | SV-260033r987769_rule | The Enterprise Voice, Video, and Messaging Session Manager must be configured to limit and reserve bandwidth based on priority of the traffic type. |
| ☐ | SV-260034r949063_rule | The Enterprise Voice, Video, and Messaging Session Manager must be configured to protect the confidentiality and integrity of transmitted configuration files, signaling, and media streams. |
| ☐ | SV-260035r949066_rule | The Enterprise Voice, Video, and Messaging Session Manager, when using locally stored user accounts, must automatically lock the account until the locked account is released by an administrator when three unsuccessful logon attempts in 15 minutes are exceeded. |
| ☐ | SV-260036r1207650_rule | For accounts using password authentication, the Enterprise Voice, Video, and Messaging Session Manager must be configured to use FIPS-validated SHA-2 or later protocol to protect the integrity of the password authentication process. |
| ☐ | SV-260037r949072_rule | The Enterprise Voice, Video, and Messaging Session Manager must generate session (call) records when concurrent logons from multiple endpoints occur. |
| ☐ | SV-260038r949075_rule | When using locally stored user accounts, the Enterprise Voice, Video, and Messaging Session Manager must generate audit records for all account creations, modifications, disabling, and termination events. |
| ☐ | SV-260039r1117247_rule | The Enterprise Voice, Video, and Messaging Session Manager must implement NIST FIPS-validated cryptography for communications sessions. |
| ☐ | SV-260040r949081_rule | The Enterprise Voice, Video, and Messaging Session Manager must be configured to use the organization authoritative time source (NTP) to maintain system time. |
| ☐ | SV-260041r949084_rule | The Enterprise Voice, Video, and Messaging Session Manager must be configured in accordance with the security configuration settings based on DOD security configuration or implementation guidance, including STIGs, NSA configuration guides, CTOs, and DTMs. |
| ☐ | SV-260042r949087_rule | The Enterprise Voice, Video, and Messaging Session Manager requiring user access authentication must provide a logout capability for user-initiated communications sessions. |
| ☐ | SV-260043r1117223_rule | The Enterprise Voice, Video, and Messaging Session Manager must be configured to apply 802.1Q VLAN tags to signaling and media traffic. |
| ☐ | SV-260044r1117223_rule | The Enterprise Voice, Video, and Messaging Session Manager must be configured to use a voice or video VLAN, separate from all other VLANs. |
| ☐ | SV-260045r1173878_rule | When using locally stored user accounts, the Enterprise Voice, Video, and Messaging Session Manager must store only cryptographic representations of passwords. |
| ☐ | SV-260046r949099_rule | The Enterprise Voice, Video, and Messaging Session Manager must be configured to use only TLS 1.2 or greater for all TLS and SSL communications. |
| ☐ | SV-260047r949102_rule | When using PKI, the Enterprise Voice, Video, and Messaging Session Manager must validate certificates used for Transport Layer Security (TLS) functions by performing RFC 5280-compliant certification path validation. |