Check: SRG-NET-000053-VVEP-00009
Unified Communications Endpoint SRG:
SRG-NET-000053-VVEP-00009
(in version v1 r0.1)
Title
The Unified Communications Endpoint must be configured to limit the number of concurrent sessions to an organizationally defined number. (Cat II impact)
Discussion
Unified Communications Endpoint management includes the ability to control the number of user sessions and limiting the number of allowed user sessions helps limit risk related to DoS attacks. Unified Communications Endpoint sessions occur peer-to-peer for media streams and client-server with session managers. For those endpoints that conference together multiple streams, the limit may be increased according to policy but a limit must still exist.
Check Content
Verify the Unified Communications Endpoint is configured to limit the number of concurrent sessions to an organizationally defined number. If the Unified Communications Endpoint is not configured to limit the number of concurrent sessions to the limit set by local policy, this is a finding.
Fix Text
Configure the Unified Communications Endpoint to limit the number of concurrent sessions to the limit set by local policy.
Additional Identifiers
Rule ID: SRG-NET-000053-VVEP-00009_rule
Vulnerability ID: SRG-NET-000053-VVEP-00009
Group Title: SRG-NET-000053-VVEP-00009
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000054 |
Limit the number of concurrent sessions for each organization-defined account and/or account type to an organization-defined number. |
Controls
Number | Title |
---|---|
AC-10 |
Concurrent Session Control |