Check: SRG-NET-000512-VVEP-00103
Enterprise Voice, Video, and Messaging Endpoint SRG:
SRG-NET-000512-VVEP-00103
(in versions v1 r2 through v1 r1)
Title
The Enterprise Voice, Video, and Messaging Endpoint must be configured to disable any auto answer features. (Cat II impact)
Discussion
An Enterprise Voice, Video, and Messaging Endpoint set to automatically answer a call with audio or video capabilities enabled risks transmitting information not intended for the caller. In the event an Enterprise Voice, Video, and Messaging Endpoint automatically answered a call during a classified meeting or discussion, potentially sensitive or classified information could be transmitted. The auto-answer feature must not be activated by a user unless the feature is required to satisfy mission requirements.
Check Content
Verify the Enterprise Voice, Video, and Messaging Endpoint is configured to disable any auto answer features. If the Enterprise Voice, Video, and Messaging Endpoint is not configured to disable auto answer features, this is a finding.
Fix Text
Configure the Enterprise Voice, Video, and Messaging Endpoint to disable auto answer features.
Additional Identifiers
Rule ID: SV-259982r956073_rule
Vulnerability ID: V-259982
Group Title: SRG-NET-000512
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000366 |
Implement the security configuration settings. |
Controls
Number | Title |
---|---|
CM-6 |
Configuration Settings |