Check: SRG-NET-000511-VVEP-00010
Enterprise Voice, Video, and Messaging Endpoint SRG:
SRG-NET-000511-VVEP-00010
(in versions v1 r2 through v1 r1)
Title
The Enterprise Voice, Video, and Messaging Endpoint must, at a minimum, offload interconnected systems in real-time and offload standalone systems weekly. (Cat II impact)
Discussion
Information stored in one location is vulnerable to accidental or incidental deletion or alteration. Offloading is a common process in information systems with limited audit storage capacity. Audit records are commonly produced by session management and border elements. Many Enterprise Voice, Video, and Messaging Endpoints are not capable of providing audit records and instead rely on session management and border elements. Enterprise Voice, Video, and Messaging Endpoints capable of producing audit records provide supplemental confirmation of monitored events. Enterprise Voice, Video, and Messaging Endpoints that support audit records must support offloading.
Check Content
Verify the Enterprise Voice, Video, and Messaging Endpoint offloads audit records in real time or weekly. If the Enterprise Voice, Video, and Messaging Endpoint does not offload audit records in real time or weekly, this is a finding.
Fix Text
Configure the Enterprise Voice, Video, and Messaging Endpoint to offload audit records in real time or weekly.
Additional Identifiers
Rule ID: SV-259978r948901_rule
Vulnerability ID: V-259978
Group Title: SRG-NET-000511
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001851 |
Transfer audit logs per organization-defined frequency to a different system, system component, or media than the system or system component conducting the logging. |
Controls
Number | Title |
---|---|
AU-4(1) |
Transfer to Alternate Storage |