Check: SRG-NET-000138-VVEP-00029
Unified Communications Endpoint SRG:
SRG-NET-000138-VVEP-00029
(in version v1 r0.1)
Title
The Unified Communications Endpoint must be configured to uniquely identify participating users. (Cat I impact)
Discussion
To assure accountability and prevent unauthenticated access, users must be identified to prevent potential misuse and compromise of the system. The Unified Communications Endpoint must display the source of an incoming call and the participant's identity to aid the user in deciding whether to answer a call. The information potentially at risk is that which can be seen in the physical area of the Unified Communications Endpoint or carried by the conference in which it is participating. This does not apply to authentication for the purpose of configuring the device itself (i.e., device management).
Check Content
Verify the Unified Communications Endpoint uniquely identifies participating users. Identification must be visible and displayed locally. If the Unified Communications Endpoint does not uniquely identify participating users, this is a finding.
Fix Text
Configure the Unified Communications Endpoint to uniquely identify participating users.
Additional Identifiers
Rule ID: SRG-NET-000138-VVEP-00029_rule
Vulnerability ID: SRG-NET-000138-VVEP-00029
Group Title: SRG-NET-000138-VVEP-00029
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000764 |
Uniquely identify and authenticate organizational users and associate that unique identification with processes acting on behalf of those users. |
Controls
Number | Title |
---|---|
IA-2 |
Identification and Authentication (organizational Users) |