DMAFB VTC STIG Checklist.pdf
PDF 835 KB Posted
- Attached to
- Davis-Monthan AFB VTC Upgrade Federal contract opportunity
- Solicitation number
- FA487720QA152
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| MXG VTC PWS 20200218.pdf | ||
| Wg VTC PWS 20200218.pdf | ||
| MXG VTC PWS 20200213.pdf | ||
| Wing VTC PWS 20200213.pdf | ||
| Wing Conference Speakers Location.pdf | ||
| MXG VTC PWS.pdf | ||
| VTC Equipment List.pdf | ||
| Wing VTC PWS.pdf | ||
| DD254 - 355 MXG.pdf | ||
| DD254 - 355 Wing.pdf | ||
| Wage Determinations #2015-5474.pdf |
Show all 11
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
STIG Vuln ID Severity Rule Title Discussion Fix Text Potential Impact Status CCI Comments Voice Video Endpoint Security Requirements Guide :: Version 1, Release:
9 Benchmark Date: 26 Apr
V-66683 medium The hardware Voice Video Endpoint must integrate into the implemented 802.1x network access control system.
IEEE 802.1x is a protocol used to control access to LAN services via a network access switchport or wireless access point that requires a device or user to authenticate to the network element and become authorized by the authentication server before accessing the network. This standard is used to activate the network access switchport limiting traffic to a specific VLAN or install traffic filters.
Implementing 802.1x port security on each access switchport denies all other MAC users, which eliminates the security risk of additional users attaching to a switch to bypass authentication. The hardware Voice Video Endpoint must be an 802.1x supplicant and integrate into the 802.1x access control system. When 802.1x is used, all devices connecting to the LAN are required to use 802.1x.
Configure the hardware Voice Video Endpoint to integrate into the implemented 802.1x network access control system.
Not Reviewed
CCI-000366
The organization implements the security configuration settings.
NIST SP 800-53 :: CM-6 b NIST SP 800-53A :: CM-6.1 (iv) NIST SP 800-53 Revision 4 :: CM- 6 b
Voice Video Endpoint Security Requirements Guide :: Version 1, Release:
9 Benchmark Date: 26 Apr
V-66685 medium The hardware Voice Video Endpoint must be an 802.1x supplicant.
IEEE 802.1x is a protocol used to control access to LAN services via a network access switchport or wireless access point that requires a device or user to authenticate to the network element and become authorized by the authentication server before accessing the network. This standard is used to activate the network access switchport limiting traffic to a specific VLAN or install traffic filters.
Implementing 802.1x port security on each access switchport denies all other MAC users, which eliminates the security risk of additional users attaching to a switch to bypass authentication. The hardware Voice Video Endpoint must be an 802.1x supplicant and integrate into the 802.1x access control system. When 802.1x is used, all devices connecting to the LAN are required to use 802.1x.
Configure the hardware Voice Video Endpoint to be an 802.1x supplicant in the implemented 802.1x network access control system.
Not Reviewed
CCI-000366
The organization implements the security configuration settings.
NIST SP 800-53 :: CM-6 b NIST SP 800-53A :: CM-6.1 (iv) NIST SP 800-53 Revision 4 :: CM- 6 b
Voice Video Endpoint Security Requirements Guide :: Version 1, Release:
9 Benchmark Date: 26 Apr
V-66687 medium The hardware Voice Video Endpoint PC port must connect to an 802.1x supplicant, or the PC port must be disabled.
IEEE 802.1x is a protocol used to control access to LAN services via a network access switchport or wireless access point that requires a device or user to authenticate to the network element and become authorized by the authentication server before accessing the network. This standard is used to activate the network access switchport limiting traffic to a specific VLAN or install traffic filters.
Implementing 802.1x port security on each access switchport denies all other MAC users, which eliminates the security risk of additional users attaching to a switch to bypass authentication. The hardware Voice Video Endpoint must be an 802.1x supplicant and integrate into the 802.1x access control system. When 802.1x is used, all devices connecting to the LAN are required to use 802.1x.
A Voice Video Endpoint with a PC port may break 802.1x LAN access control mechanisms when the network access switchport is authorized during the Voice Video Endpoint authentication to the network. This condition may permit devices connected to the PC port to access the LAN. The access switchport can b f d f h f ll d
Configure the hardware Voice Video Endpoint PC port to connect to an 802.1x supplicant in the implemented 802.1x network access control system or be disabled.
Not Reviewed
CCI-000366
The organization implements the security configuration settings.
NIST SP 800-53 :: CM-6 b NIST SP 800-53A :: CM-6.1 (iv) NIST SP 800-53 Revision 4 :: CM- 6 b
Voice Video Endpoint Security Requirements Guide :: Version 1, Release:
9 Benchmark Date: 26 Apr
V-66689 medium The unused hardware Voice Video Endpoint PC port must be disabled.
IEEE 802.1x is a protocol used to control access to LAN services via a network access switchport or wireless access point that requires a device or user to authenticate to the network element and become authorized by the authentication server before accessing the network. This standard is used to activate the network access switchport limiting traffic to a specific VLAN or install traffic filters.
Implementing 802.1x port security on each access switchport denies all other MAC users, which eliminates the security risk of additional users attaching to a switch to bypass authentication. The hardware Voice Video Endpoint must be an 802.1x supplicant and integrate into the 802.1x access control system. When 802.1x is used, all devices connecting to the LAN are required to use 802.1x.
A Voice Video Endpoint with a PC port may break 802.1x LAN access control mechanisms when the network access switchport is authorized during the Voice Video Endpoint authentication to the network. This condition may permit devices connected to the PC port to access the LAN. Daisy chaining devices on a i l LAN d d b 802 1 b
Configure the unused hardware Video Endpoint PC port to be disabled.
Not Reviewed
CCI-000366
The organization implements the security configuration settings.
NIST SP 800-53 :: CM-6 b NIST SP 800-53A :: CM-6.1 (iv) NIST SP 800-53 Revision 4 :: CM- 6 b
Security Requirements Guide :: Version 1, Release:
9 Benchmark Date: 26 Apr
V-66691 medium The hardware Voice Video Endpoint with a PC port must have the switchport configured as single-host or enable 802.1x multi-domain authentication.
IEEE 802.1x is a protocol used to control access to LAN services via a network access switchport or wireless access point that requires a device or user to authenticate to the network element and become authorized by the authentication server before accessing the network. This standard is used to activate the network access switchport limiting traffic to a specific VLAN or install traffic filters.
Implementing 802.1x port security on each access switchport denies all other MAC users, which eliminates the security risk of additional users attaching to a switch to bypass authentication. The hardware Voice Video Endpoint must be an 802.1x supplicant and integrate into the 802.1x access control system. When 802.1x is used, all devices connecting to the LAN are required to use 802.1x.
A Voice Video Endpoint with a PC port may break 802.1x LAN access control mechanisms when the network access switchport is authorized during the Voice Video Endpoint authentication to the network. This condition may permit devices connected to the PC port to access the LAN. Daisy chaining devices on a i l LAN d d b 802 1 b
Configure the hardware Voice Video Endpoint with a PC port to have the switchport configured as single-host or enable 802.1x multi-domain authentication.
Not Reviewed
CCI-000366
The organization implements the security configuration settings.
NIST SP 800-53 :: CM-6 b NIST SP 800-53A :: CM-6.1 (iv) NIST SP 800-53 Revision 4 :: CM- 6 b
Voice Video Endpoint Security Requirements Guide :: Version 1, Release:
9 Benchmark Date: 26 Apr
V-66693 medium The hardware Voice Video Endpoint not supporting 802.1x must be configured to use MAC Authentication Bypass (MAB) on the access switchport.
IEEE 802.1x is a protocol used to control access to LAN services via a network access switchport or wireless access point that requires a device or user to authenticate to the network element and become authorized by the authentication server before accessing the network. This standard is used to activate the network access switchport limiting traffic to a specific VLAN or install traffic filters.
Implementing 802.1x port security on each access switchport denies all other MAC users, which eliminates the security risk of additional users attaching to a switch to bypass authentication. The hardware Voice Video Endpoint must be an 802.1x supplicant and integrate into the 802.1x access control system. When 802.1x is used, all devices connecting to the LAN are required to use 802.1x.
A Voice Video Endpoint with a PC port may break 802.1x LAN access control mechanisms when the network access switchport is authorized during the Voice Video Endpoint authentication to the network. This condition may permit devices connected to the PC port to access the LAN. Daisy chaining devices on a i l LAN d d b 802 1 b
Configure the hardware Voice Video Endpoint not supporting 802.1x to use MAB on the access switchport.
Not Reviewed
CCI-000366
The organization implements the security configuration settings.
NIST SP 800-53 :: CM-6 b NIST SP 800-53A :: CM-6.1 (iv) NIST SP 800-53 Revision 4 :: CM- 6 b
Voice Video Endpoint Security Requirements Guide :: Version 1, Release:
9 Benchmark Date: 26 Apr
V-66699 medium The Voice Video Endpoint must limit the number of concurrent sessions to two
(2) users.
Voice video endpoint management includes the ability to control the number of user sessions and limiting the number of allowed user sessions helps limit risk related to DoS attacks. Voice video endpoint sessions occur peer-to-peer for media streams and client-server with session managers. For those endpoints that conference together multiple streams, the limit may be increased according to policy but a limit must still exist.
Configure the Voice Video Endpoint to limit the number of concurrent sessions to two users or the limit set by local policy.
Not Reviewed
CCI-000054
The information system limits the number of concurrent sessions for each organization-defined account and/or account type to an organization-defined number of sessions.
NIST SP 800-53 :: AC-10
NIST SP 800-53A :: AC-10.1 (ii) NIST SP 800-53 Revision 4 :: AC-
Voice Video Endpoint Security Requirements Guide :: Version 1, Release:
9 Benchmark Date: 26 Apr
V-66701 medium The hardware Voice Video Endpoint must apply 802.1Q VLAN tags to signaling and media traffic.
When Voice Video Endpoints do not dynamically assign 802.1Q VLAN tags as data is created and combined, it is possible the VLAN tags will not correctly reflect the data type with which they are associated. VLAN tags are used as security attributes. These attributes are typically associated with signaling and media streams within the application and are used to enable the implementation of access control and flow control policies. Security labels for packets may include traffic flow information (e.g., source, destination, protocol combination), traffic classification based on QoS markings for preferred treatment, and VLAN identification.
Virtualized networking is used to separate voice video traffic from other types of traffic, such as data, management, and other special types. VLANs provide segmentation at layer 2.
Virtual Routing and Forwarding (VRF) provides segmentation at layer 3, and works with Multiprotocol Label Switching (MPLS) for enterprise and WAN environments. When VRF is used without MPLS, it is referred to as VRF lite. For Voice Video systems, subnets, d d d
Configure the hardware Voice Video Endpoint to apply 802.1Q VLAN tags to signaling and media traffic.
Not Reviewed
CCI-000366
The organization implements the security configuration settings.
NIST SP 800-53 :: CM-6 b NIST SP 800-53A :: CM-6.1 (iv) NIST SP 800-53 Revision 4 :: CM- 6 b
CCI-002272
The information system dynamically associates security attributes with organization-defined objects in accordance with organization-defined security policies as information is created and combined.
NIST SP 800-53 Revision 4 :: AC- 16 (1)
Guide :: Version 1, Release:
9 Benchmark Date: 26 Apr
V-66703 medium The hardware Voice Video Endpoint must use a voice video VLAN, separate from all other VLANs.
Virtualized networking is used to separate voice video traffic from other types of traffic, such as data, management, and other special types. VLANs provide segmentation at layer 2.
Virtual Routing and Forwarding (VRF) provides segmentation at layer 3, and works with Multiprotocol Label Switching (MPLS) for enterprise and WAN environments. When VRF is used without MPLS, it is referred to as VRF lite. For Voice Video systems, subnets, VLANs, and VRFs are used to separate media and signaling streams from all other traffic.
Configure the hardware Voice Video Endpoint to use a voice video VLAN separate from all other VLANs.
Not Reviewed
CCI-000366
The organization implements the security configuration settings.
NIST SP 800-53 :: CM-6 b NIST SP 800-53A :: CM-6.1 (iv) NIST SP 800-53 Revision 4 :: CM- 6 b
CCI-002272
The information system dynamically associates security attributes with organization-defined objects in accordance with organization-defined security policies as information is created and combined.
NIST SP 800-53 Revision 4 :: AC- 16 (1)
Voice Video Endpoint Security Requirements Guide :: Version 1, Release:
9 Benchmark Date: 26 Apr
V-66705 medium The hardware Voice Video Endpoint PC port must maintain VLAN separation from the voice video VLAN, or be disabled.
Virtualized networking is used to separate voice video traffic from other types of traffic, such as data, management, and other special types. VLANs provide segmentation at layer 2.
Virtual Routing and Forwarding (VRF) provides segmentation at layer 3, and works with Multiprotocol Label Switching (MPLS) for enterprise and WAN environments. When VRF is used without MPLS, it is referred to as VRF lite. For Voice Video systems, subnets, VLANs, and VRFs are used to separate media and signaling streams from all other traffic.
Configure the hardware Voice Video Endpoint PC port to maintain VLAN separation from the voice video VLAN or be disabled.
Not Reviewed
CCI-000366
The organization implements the security configuration settings.
NIST SP 800-53 :: CM-6 b NIST SP 800-53A :: CM-6.1 (iv) NIST SP 800-53 Revision 4 :: CM- 6 b
CCI-001424
The information system dynamically associates security attributes with organization-defined subjects in accordance with organization-defined security policies as information is created and combined.
NIST SP 800-53 :: AC-16 (1)
NIST SP 800-53A :: AC-16 (1).1
NIST SP 800-53 Revision 4 :: AC- 16 (1)
Voice Video Endpoint Security Requirements Guide :: Version 1, Release:
9 Benchmark Date: 26 Apr
V-66707 medium The Voice Video Endpoint must block both inbound and outbound communications traffic between Unified Capability (UC) and Videoconferencing (VC) clients independently configured by end users and external service providers for voice and video.
Various communication services such as public VoIP and Instant Messaging services route traffic over their own networks and are stored on their own servers; therefore, that traffic can be accessed at any time by the provider and potentially intercepted.
Communication clients independently configured by end users and external service providers include, for example, instant messaging clients. Traffic blocking does not apply to communication clients that are configured by organizations to perform authorized functions.
Configure the Voice Video Endpoint to block both inbound and outbound communications traffic between UC and VC clients independently configured by end users and external service providers.
Not Reviewed
CCI-000366
The organization implements the security configuration settings.
NIST SP 800-53 :: CM-6 b NIST SP 800-53A :: CM-6.1 (iv) NIST SP 800-53 Revision 4 :: CM- 6 b
CCI-002409
The information system blocks both inbound and outbound communications traffic between organization-defined communication clients that are independently configured by end users and external service providers.
NIST SP 800-53 Revision 4 :: SC- 7 (19)
Voice Video Endpoint Security Requirements Guide :: Version 1, Release:
9 Benchmark Date: 26 Apr
V-66709 medium The Voice Video Endpoint must implement replay-resistant authentication mechanisms for network access.
A replay attack may enable an unauthorized user to gain access to the application.
Authentication sessions between the authenticator and the application validating the user credentials must not be vulnerable to a replay attack. An authentication process resists replay attacks if it is impractical to achieve a successful authentication by recording and replaying a previous authentication message. Voice video endpoints often use passwords or PINs that can be easily exploited.
This requirement only applies to components where this is specific to the function of the device or has the concept of an organizational user. This does not apply to authentication for the purpose of configuring the device itself (i.e., device management).
Configure the Voice Video Endpoint to implement replay-resistant authentication mechanisms for network access.
Not Reviewed
CCI-001942
The information system implements replay-resistant authentication mechanisms for network access to non-privileged accounts.
NIST SP 800-53 Revision 4 :: IA-2 (9)
Guide :: Version 1, Release:
9 Benchmark Date: 26 Apr
V-66711 medium The hardware Voice Video Endpoint using SIP or AS-SIP signaling must prevent cross-site scripting attacks caused by improper filtering or validation of the content of SIP invitation fields.
A cross-site scripting vulnerability has been demonstrated by adding scripting code to the "From:" field in the SIP invite. Upon receiving the invite, the embedded code can be executed by a vulnerable embedded web server to download additional malicious code and launch an attack. The demonstration of the vulnerability also exists on www.securityfocus.com under Bugtraq ID:
25987, which pops up a specific alert box on the user’s workstation after downloading a SIP invite.
While this vulnerability has been demonstrated on a specific IP phone, it could potentially affect all SIP-based endpoints or clients and their signaling partners. This vulnerability is a result of improper filtering or validation of the content of the various fields in the SIP invite and potentially the Session Description Protocol (SDP) portion of the invite. The injected code potentially causes malicious code to be run on the target device, to include an endpoint (hard or soft), a session controller, or any other SIP signaling partner. Additionally, this vulnerability may affect applications other than SIP VoIP clients, h IM li A i il l bili
Configure the hardware Voice Video Endpoint using SIP or AS-SIP signaling to prevent cross-site scripting attacks caused by improper filtering or validation of the content of SIP invitation fields.
Not Reviewed
CCI-001942
The information system implements replay-resistant authentication mechanisms for network access to non-privileged accounts.
NIST SP 800-53 Revision 4 :: IA-2 (9)
Voice Video Endpoint Security Requirements Guide :: Version 1, Release:
9 Benchmark Date: 26 Apr
V-66713 high The Voice Video Endpoint must protect the integrity of transmitted configuration files from the Voice Video Session Manager.
Without protection of the transmitted information, confidentiality and integrity may be compromised as unprotected communications can be intercepted and either read or altered. When Voice Video Endpoint configuration files traverse a network without encryption for confidentiality, system information can be intercepted by an adversary. Encryption of the configuration files mitigates this vulnerability. However, TFTP is the most common protocol used for configuration file transfers and does not natively encrypt data.
The Cisco TFTP implementation for VoIP systems uses encryption to both store and transfer configuration files. Refer to the “CISCO-UCM-TFTP� Vulnerability Analysis report provided by the Protocols, Ports, and Services management site for more details.
Integrity checks during the transmission of configuration files ensure no changes have been introduced by adversarial attacks. TLS can be utilized to secure SIP and SCCP signaling by configuring the session manager in a secure mode.
DoD-to-DoD voice communications are ll id d i i i
Configure the Voice Video Endpoint to protect the integrity of transmitted configuration files from the Voice Video Session Manager.
Not Reviewed
CCI-002418
The information system protects the confidentiality and/or integrity of transmitted information.
NIST SP 800-53 Revision 4 :: SC-
Voice Video Endpoint Security Requirements Guide :: Version 1, Release:
9 Benchmark Date: 26 Apr
V-66715 high The Voice Video Endpoint must protect the confidentiality of transmitted configuration files from the Voice Video Session Manager.
Without protection of the transmitted information, confidentiality and integrity may be compromised as unprotected communications can be intercepted and either read or altered. When Voice Video Endpoint configuration files traverse a network without encryption for confidentiality, system information can be intercepted by an adversary. Encryption of the configuration files mitigates this vulnerability. However, TFTP is the most common protocol used for configuration file transfers and does not natively encrypt data.
The Cisco TFTP implementation for VoIP systems uses encryption to both store and transfer configuration files. Refer to the “CISCO-UCM-TFTP� Vulnerability Analysis report provided by the Protocols, Ports, and Services management site for more details.
Integrity checks during the transmission of configuration files ensure no changes have been introduced by adversarial attacks. TLS can be utilized to secure SIP and SCCP signaling by configuring the session manager in a secure mode.
DoD-to-DoD voice communications are ll d d
Configure the Voice Video Endpoint to protect the confidentiality of transmitted configuration files from the Voice Video Session Manager.
Not Reviewed
CCI-002418
The information system protects the confidentiality and/or integrity of transmitted information.
NIST SP 800-53 Revision 4 :: SC-
Voice Video Endpoint Security Requirements Guide :: Version 1, Release:
9 Benchmark Date: 26 Apr
V-66717 high The Voice Video Endpoint must dynamically implement configuration file changes.
Configuration management includes the management of security features and assurances through control of changes made to device hardware, software, and firmware throughout the life cycle of a product. Secure configuration management relies on performance and functional attributes of products to determine the appropriate security features and assurances used to measure a system configuration state. When configuration changes are made, it is critical for those changes to be implemented by the Voice Video Endpoint as quickly as possible.
This ensures that Voice Video Endpoints communicate using the correct address books, session managers, gateways, and border elements.
Configure the Voice Video Endpoint to dynamically implement configuration file changes.
Not Reviewed
CCI-000213
The information system enforces approved authorizations for logical access to information and system resources in accordance with applicable access control policies.
NIST SP 800-53 :: AC-3
NIST SP 800-53A :: AC-3.1
Guide :: Version 1, Release:
9 Benchmark Date: 26 Apr
V-66719 medium The Voice Video Endpoint must display the Standard Mandatory DoD Notice and Consent Banner before granting access to the network.
Display of a standardized and approved use notification before granting access to the network ensures privacy and security notification verbiage used is consistent with applicable federal laws, Executive Orders, directives, policies, regulations, standards, and guidance. System use notifications are required only for access via logon interfaces with human users and are not required when such human interfaces do not exist. This requirement applies to Voice Video Endpoints that have the concept of a user account and have the logon function residing on the network element.
The banner must be formatted in accordance with current policy. Use the following verbiage for network elements that can accommodate banners of 1300 characters:
"You are accessing a U.S. Government (USG) Information System (IS) that is provided for USG-authorized use only.
By using this IS (which includes any device attached to this IS), you consent to the following conditions:
Th USG i l i d i
Configure the Unified Capabilities (UC) or Video Conferencing (VC) software client Voice Video Endpoint to display the Standard Mandatory DoD Notice and Consent Banner before granting access to the network.
Not Reviewed
CCI-000048
The information system displays an organization-defined system use notification message or banner before granting access to the system that provides privacy and security notices consistent with applicable federal laws, Executive Orders, directives, policies, regulations, standards, and guidance.
NIST SP 800-53 :: AC-8 a NIST SP 800-53A :: AC-8.1 (ii) NIST SP 800-53 Revision 4 :: AC- 8 a
Voice Video Endpoint Security Requirements Guide :: Version 1, Release:
9 Benchmark Date: 26 Apr
V-66725 medium The Voice Video Endpoint must retain the Standard Mandatory DoD Notice and Consent Banner on the screen until users acknowledge the usage conditions and take explicit actions to log on for further access.
The banner must be acknowledged by the user prior to allowing the user access to the network. This provides assurance that the user has seen the message and accepted the conditions for access. If the consent banner is not acknowledged by the user, DoD will not be in compliance with system use notifications required by law. To establish acceptance of the application usage policy, a click-through banner at application logon is required. The network element must prevent further activity until the user executes a positive action to manifest agreement by clicking on a box indicating "OK". System use notifications are required only for access via logon interfaces with human users and are not required when such human interfaces do not exist. This requirement applies to Voice Video Endpoints that have the concept of a user account and have the logon function residing on the network element.
Configure the Unified Capabilities (UC) or Video Conferencing (VC) software client Voice Video Endpoint to retain the Standard Mandatory DoD Notice and Consent Banner on the screen until users acknowledge the usage conditions and take explicit actions to log on for further access.
Not Reviewed
CCI-000050
The information system retains the notification message or banner on the screen until users acknowledge the usage conditions and take explicit actions to log on to or further access.
NIST SP 800-53 :: AC-8 b NIST SP 800-53A :: AC-8.1 (iii) NIST SP 800-53 Revision 4 :: AC- 8 b
Voice Video Endpoint Security Requirements Guide :: Version 1, Release:
9 Benchmark Date: 26 Apr
V-66727 medium The Voice Video Endpoint must produce session (call detail) records containing what type of connection occurred.
Session records are commonly produced by session management and border elements.
Many Voice Video Endpoints are not capable of providing session records and instead rely on session management and border elements. Voice video endpoints capable of producing session records provide supplemental confirmation of monitored events. Voice video endpoints that communicate beyond these defined environments must generate session records.
Session record content that may be necessary to satisfy this requirement includes, for example, type of connection, connection origination, time stamps, outcome, user identities, and user identifiers. Additionally, an adversary must not be able to modify or delete session records. Detailed records are typically produced by the session manager but can be augmented by non-telephone endpoint records.
Configure the Voice Video Endpoint to produce session records containing what type of connection occurred.
Not Reviewed
CCI-000130
The information system generates audit records containing information that establishes what type of event occurred.
NIST SP 800-53 :: AU-3
NIST SP 800-53A :: AU-3.1
NIST SP 800-53 Revision 4 :: AU-
Voice Video Endpoint Security Requirements Guide :: Version 1, Release:
9 Benchmark Date: 26 Apr
V-66729 medium The Voice Video Endpoint must produce session (call detail) records containing when (date and time) the connection occurred.
Session records are commonly produced by session management and border elements.
Many Voice Video Endpoints are not capable of providing session records and instead rely on session management and border elements. Voice video endpoints capable of producing session records provide supplemental confirmation of monitored events. Voice video endpoints that communicate beyond these defined environments must generate session records.
Session record content that may be necessary to satisfy this requirement includes, for example, type of connection, connection origination, time stamps, outcome, user identities, and user identifiers. Additionally, an adversary must not be able to modify or delete session records. Detailed records are typically produced by the session manager but can be augmented by non-telephone endpoint records.
Configure the Voice Video Endpoint to produce session records containing the date and time when the connection occurred.
Not Reviewed
CCI-000131
The information system generates audit records containing information that establishes when an event occurred.
NIST SP 800-53 :: AU-3
NIST SP 800-53A :: AU-3.1
NIST SP 800-53 Revision 4 :: AU-
Guide :: Version 1, Release:
9 Benchmark Date: 26 Apr
V-66731 medium The Voice Video Endpoint must produce session (call detail) records containing where the connection occurred.
Session records are commonly produced by session management and border elements.
Many Voice Video Endpoints are not capable of providing session records and instead rely on session management and border elements. Voice video endpoints capable of producing session records provide supplemental confirmation of monitored events. Voice video endpoints that communicate beyond these defined environments must generate session records.
Session record content that may be necessary to satisfy this requirement includes, for example, type of connection, connection origination, time stamps, outcome, user identities, and user identifiers. Additionally, an adversary must not be able to modify or delete session records. Detailed records are typically produced by the session manager but can be augmented by non-telephone endpoint records.
Configure the Voice Video Endpoint to produce session records containing where the connection occurred.
Not Reviewed
CCI-000132
The information system generates audit records containing information that establishes where the event occurred.
NIST SP 800-53 :: AU-3
NIST SP 800-53A :: AU-3.1
NIST SP 800-53 Revision 4 :: AU-
Voice Video Endpoint Security Requirements Guide :: Version 1, Release:
9 Benchmark Date: 26 Apr
V-66733 medium The Voice Video Endpoint must produce session (call detail) records containing the outcome of the connection.
Session records are commonly produced by session management and border elements.
Many Voice Video Endpoints are not capable of providing session records and instead rely on session management and border elements. Voice video endpoints capable of producing session records provide supplemental confirmation of monitored events. Voice video endpoints that communicate beyond these defined environments must generate session records.
Session record content that may be necessary to satisfy this requirement includes, for example, type of connection, connection origination, time stamps, outcome, user identities, and user identifiers. Additionally, an adversary must not be able to modify or delete session records. Detailed records are typically produced by the session manager but can be augmented by non-telephone endpoint records.
Configure the Voice Video Endpoint to produce session records containing the outcome of the connection.
Not Reviewed
CCI-000134
The information system generates audit records containing information that establishes the outcome of the event.
NIST SP 800-53 :: AU-3
NIST SP 800-53A :: AU-3.1
NIST SP 800-53 Revision 4 :: AU-
Voice Video Endpoint Security Requirements Guide :: Version 1, Release:
9 Benchmark Date: 26 Apr
V-66735 medium The Voice Video Endpoint must produce session (call detail) records containing the identity of all users.
Session records are commonly produced by session management and border elements.
Many Voice Video Endpoints are not capable of providing session records and instead rely on session management and border elements. Voice video endpoints capable of producing session records provide supplemental confirmation of monitored events. Voice video endpoints that communicate beyond these defined environments must generate session records.
Session record content that may be necessary to satisfy this requirement includes, for example, type of connection, connection origination, time stamps, outcome, user identities, and user identifiers. Additionally, an adversary must not be able to modify or delete session records. Detailed records are typically produced by the session manager but can be augmented by non-telephone endpoint records.
Configure the Voice Video Endpoint to produce session records containing the identity of all users on the call.
Not Reviewed
CCI-001487
The information system generates audit records containing information that establishes the identity of any individuals or subjects associated with the event.
NIST SP 800-53 :: AU-3
NIST SP 800-53A :: AU-3.1
NIST SP 800-53 Revision 4 :: AU-
Voice Video Endpoint Security Requirements Guide :: Version 1, Release:
9 Benchmark Date: 26 Apr
V-66737 medium The Voice Video Endpoint must provide session (call detail) record generation capability.
Session records are commonly produced by session management and border elements.
Many Voice Video Endpoints are not capable of providing session records and instead rely on session management and border elements. Voice video endpoints capable of producing session records provide supplemental confirmation of monitored events. Voice video endpoints that communicate beyond these defined environments must generate session records.
Session records for Voice Video systems are generally handled in a similar fashion to audit records for other systems and are used for billing, usage analysis, and record support for actions taken. Detailed records are typically produced by the session manager but can be augmented by non-telephone endpoint records.
Configure the Voice Video Endpoint to provide session record generation capability.
Not Reviewed
CCI-000169
The information system provides audit record generation capability for the auditable events defined in AU- 2 a at organization-defined information system components.
NIST SP 800-53 :: AU-12 a NIST SP 800-53A :: AU-12.1 (ii) NIST SP 800-53 Revision 4 :: AU- 12 a
Guide :: Version 1, Release:
9 Benchmark Date: 26 Apr
V-66739 high The Voice Video Endpoint must terminate all network connections associated with a communications session at the end of the session.
Terminating an idle session within a short time period reduces the window of opportunity for unauthorized personnel to take control of a management session enabled on the console or console port that has been left unattended. In addition, quickly terminating an idle session will also free up resources committed by the managed network element. Terminating network connections associated with communications sessions includes, de-allocating associated TCP/IP address/port pairs at the device or operating system level, and de-allocating networking assignments at the application level if multiple application sessions are using a single, operating system level network connection.
Configure the Voice Video Endpoint to terminate all network connections associated with a communications session at the end of the session.
Not Reviewed
CCI-001133
The information system terminates the network connection associated with a communications session at the end of the session or after an organization-defined time period of inactivity.
NIST SP 800-53 :: SC-10
NIST SP 800-53A :: SC-10.1 (ii) NIST SP 800-53 Revision 4 :: SC-
Voice Video Endpoint Security Requirements Guide :: Version 1, Release:
9 Benchmark Date: 26 Apr
V-66741 high The Voice Video Endpoint used for videoconferencing must uniquely identify participating users.
To assure accountability and prevent unauthenticated access, users must be identified to prevent potential misuse and compromise of the system. The Voice Video Endpoint must display the source of an incoming call and the participant's identity to aid the user in deciding whether to answer a call. The information potentially at risk is that which can be seen in the physical area of the Voice Video Endpoint or carried by the conference in which it is participating.
This does not apply to authentication for the purpose of configuring the device itself (i.e., device management).
Configure the Voice Video Endpoint used for videoconferencing to uniquely identify participating users.
Not Reviewed
CCI-000764
The information system uniquely identifies and authenticates organizational users (or processes acting on behalf of organizational users).
NIST SP 800-53 :: IA-2
NIST SP 800-53A :: IA-2.1
NIST SP 800-53 Revision 4 :: IA-2
Voice Video Endpoint Security Requirements Guide :: Version 1, Release:
9 Benchmark Date: 26 Apr
V-66743 medium The Voice Video Endpoint used for videoconferencing must accept a Common Access Card (CAC) or derived credentials.
The use of CAC or derived credentials facilitates standardization and reduces the risk of unauthorized access. DoD has mandated the use of the CAC to support identity management and personal authentication for systems covered under HSPD 12, as well as a primary component of layered protection for national security systems.
Configure the Voice Video Endpoint used for videoconferencing to accept a CAC or derived credentials.
Not Reviewed
CCI-001953
The information system accepts Personal Identity Verification (PIV) credentials.
NIST SP 800-53 Revision 4 :: IA-2 (12)
Voice Video Endpoint Security Requirements Guide :: Version 1, Release:
9 Benchmark Date: 26 Apr
V-66745 medium The Voice Video Endpoint used for videoconferencing must electronically verify the Common Access Card (CAC) or derived credentials.
The use of CAC or derived credentials facilitates standardization and reduces the risk of unauthorized access. DoD has mandated the use of the CAC to support identity management and personal authentication for systems covered under HSPD 12, as well as a primary component of layered protection for national security systems.
Configure the Voice Video Endpoint used for videoconferencing to electronically verify the CAC or derived credentials.
Not Reviewed
CCI-001954
The information system electronically verifies Personal Identity Verification (PIV) credentials.
NIST SP 800-53 Revision 4 :: IA-2 (12)
Voice Video Endpoint Security Requirements Guide :: Version 1, Release:
9 Benchmark Date: 26 Apr
V-66747 medium The Voice Video Endpoint used for videoconferencing must use multifactor authentication for network access.
To assure accountability and prevent unauthenticated access, users must utilize multifactor authentication to prevent potential misuse and compromise of the system. Multifactor authentication uses two or more factors to achieve authentication.
Factors include:
(i) Something you know (e.g., password/PIN);
(ii) Something you have (e.g., cryptographic identification device, token); or
(iii) Something you are (e.g., biometric).
Network access is any access to an application by a user (or process acting on behalf of a user) where said access is obtained through a network connection. The DoD CAC with DoD-approved PKI is an example of multifactor authentication.
This does not apply to authentication for the purpose of configuring the device itself (i.e., device management).
Configure the Voice Video Endpoint used for videoconferencing to use multifactor authentication for network access.
Not Reviewed
CCI-000766
The information system implements multifactor authentication for network access to non-privileged accounts.
NIST SP 800-53 :: IA-2 (2)
NIST SP 800-53A :: IA-2 (2).1
NIST SP 800-53 Revision 4 :: IA-2 (2)
Voice Video Endpoint Security Requirements Guide :: Version 1, Release:
9 Benchmark Date: 26 Apr
V-66749 high The Voice Video Endpoint, when using passwords or PINs for authentication or authorization, must cryptographically-protect the transmission.
Passwords need to be protected at all times and encryption is the standard method for protecting passwords. If passwords are not encrypted, they can be plainly read (i.e., clear text) and easily compromised.
This does not apply to authentication for the purpose of configuring the device itself (management).
Configure the Voice Video Endpoint, when using passwords or PINs for authentication or authorization, to cryptographically protect the transmission.
Not Reviewed
CCI-000197
The information system, for password-based authentication, transmits only encrypted representations of passwords.
NIST SP 800-53 :: IA-5 (1) (c) NIST SP 800-53A :: IA-5 (1).1 (v) NIST SP 800-53 Revision 4 :: IA-5
(1) (c)
Voice Video Endpoint Security Requirements Guide :: Version 1, Release:
9 Benchmark Date: 26 Apr
V-66751 high When using PKI-based authentication, the Voice Video Endpoint must enforce authorized access to the corresponding private key.
If the private key is discovered, an attacker can use the key to authenticate as an authorized user and gain access to the network infrastructure. The cornerstone of the PKI is the private key used to encrypt or digitally sign information. If the private key is stolen, this will lead to the compromise of the authentication and non-repudiation gained through PKI because the attacker can use the private key to authenticate to network devices.
This does not apply to authentication for the purpose of configuring the device itself (management).
Configure the Voice Video Endpoint, when using PKI-based authentication, to enforce authorized access to the corresponding private key.
Not Reviewed
CCI-000186
The information system, for PKI-based authentication enforces authorized access to the corresponding private key.
NIST SP 800-53 :: IA-5 (2)
NIST SP 800-53A :: IA-5 (2).1
NIST SP 800-53 Revision 4 :: IA-5 (2)
Guide :: Version 1, Release:
9 Benchmark Date: 26 Apr
V-66753 high When using PKI-based authentication, the Voice Video Endpoint used for videoconferencing must validate certificates by constructing a certification path (which includes status information) to an accepted trust anchor.
Without path validation, an informed trust decision by the relying party cannot be made when presented with any certificate not already explicitly trusted. A trust anchor is an authoritative entity represented via a public key. Within a chain of trust, the top entity to be trusted is the "root certificate" or "trust anchors" such as a Certification Authority (CA). A certification path starts with the subject certificate and proceeds through a number of intermediate certificates up to a trusted root certificate, typically issued by a trusted CA.
This requirement verifies that a certification path to an accepted trust anchor is used for certificate validation and that the path includes status information. Path validation is necessary for a relying party to make an informed trust decision when presented with any certificate not already explicitly trusted.
Status information for certification paths includes certificate revocation lists or online certificate status protocol responses.
Validation of the certificate status information is out of scope for this requirement.
Configure the Voice Video Endpoint used for videoconferencing, when using PKI-based authentication, to validate certificates by constructing a certification path, including status information, to an accepted trust anchor.
Not Reviewed
CCI-000185
The information system, for PKI-based authentication validates certifications by constructing and verifying a certification path to an accepted trust anchor including checking certificate status information.
NIST SP 800-53 :: IA-5 (2)
NIST SP 800-53A :: IA-5 (2).1
NIST SP 800-53 Revision 4 :: IA-5
(2) (a)
Voice Video Endpoint Security Requirements Guide :: Version 1, Release:
9 Benchmark Date: 26 Apr
V-66755 medium When using PKI-based authentication, the Voice Video Endpoint used for videoconferencing must implement a local cache of revocation data to support path discovery and validation in the event the network path becomes unavailable.
Without configuring a local cache of revocation data, there is the potential to allow access to users who are no longer authorized (users with revoked certificates).
This does not apply to authentication for the purpose of configuring the device itself (i.e., device management).
Configure the Voice Video Endpoint used for videoconferencing, when using PKI-based authentication, to implement a local cache of revocation data to support path discovery and validation in the event the network path becomes unavailable.
Not Reviewed
CCI-001991
The information system, for PKI-based authentication, implements a local cache of revocation data to support path discovery and validation in case of inability to access revocation information via the network.
NIST SP 800-53 Revision 4 :: IA-5
(2) (d)
Voice Video Endpoint Security Requirements Guide :: Version 1, Release:
9 Benchmark Date: 26 Apr
V-66757 high The Voice Video Endpoint must use encryption for signaling and media traffic.
Without protection of the transmitted information, confidentiality and integrity may be compromised as unprotected communications can be intercepted and either read or altered. TLS can be utilized to secure SIP and SCCP signaling by configuring the session manager in a secure mode.
DoD-to-DoD voice communications are generally considered to contain sensitive information and therefore DoD voice and data traffic crossing the unclassified DISN must be encrypted. Cryptographic mechanisms such as Media Access Control Security (MACsec) implemented to protect information include cryptographic hash functions that have common application in digital signatures, checksums, and message authentication codes.
Configure the Voice Video Endpoint to use encryption for signaling and media traffic.
Not Reviewed
CCI-002418
The information system protects the confidentiality and/or integrity of transmitted information.
NIST SP 800-53 Revision 4 :: SC-
Voice Video Endpoint Security Requirements Guide :: Version 1, Release:
9 Benchmark Date: 26 Apr
V-66759 high The Voice Video Endpoint processing classified information over public networks must implement NSA-approved cryptography.
Use of weak or untested encryption algorithms undermines the purposes of utilizing encryption to protect data. The network element must implement cryptographic modules adhering to the higher standards approved by the federal government since this provides assurance they have been tested and validated.
Configure the Voice Video Endpoint processing classified information over public networks to implement NSA-approved cryptography.
Not Reviewed
CCI-002450
The information system implements organization-defined cryptographic uses and type of cryptography required for each use in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, and standards.
NIST SP 800-53 Revision 4 :: SC-
Voice Video Endpoint Security Requirements Guide :: Version 1, Release:
9 Benchmark Date: 26 Apr
V-66761 high The Voice Video Endpoint processing unclassified information must implement NIST FIPS-validated cryptography.
Use of weak or untested encryption algorithms undermines the purposes of utilizing encryption to protect data. The network element must implement cryptographic modules adhering to the higher standards approved by the federal government since this provides assurance they have been tested and validated.
Configure the Voice Video Endpoint processing unclassified information to implement NIST FIPS-validated cryptography.
Not Reviewed
CCI-002450
The information system implements organization-defined cryptographic uses and type of cryptography required for each use in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, and standards.
NIST SP 800-53 Revision 4 :: SC-
Voice Video Endpoint Security Requirements Guide :: Version 1, Release:
9 Benchmark Date: 26 Apr
V-66763 high The Voice Video Endpoint processing unclassified information must implement NIST FIPS-validated cryptography to generate cryptographic hashes.
Use of weak or untested encryption algorithms undermines the purposes of utilizing encryption to protect data. The network element must implement cryptographic modules adhering to the higher standards approved by the federal government since this provides assurance they have been tested and validated.
Configure the Voice Video Endpoint processing unclassified information to implement NIST FIPS-validated cryptography to generate cryptographic hashes.
Not Reviewed
CCI-002450
The information system implements organization-defined cryptographic uses and type of cryptography required for each use in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, and standards.
NIST SP 800-53 Revision 4 :: SC-
Guide :: Version 1, Release:
9 Benchmark Date: 26 Apr
V-66765 medium The Voice Video Endpoint must provide an explicit indication of current participants in all Videoconference (VC)-based and IP-based online meetings and conferences.
Providing an explicit indication of current participants in teleconferences helps to prevent unauthorized individuals from participating in collaborative…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .