Check: SRG-NET-000236-VVEP-00043
Unified Communications Endpoint SRG:
SRG-NET-000236-VVEP-00043
(in version v1 r0.1)
Title
In the event of a device failure, Unified Communications Endpoints must preserve any information necessary to determine cause of failure and return to operations with least disruption to service. (Cat II impact)
Discussion
Failure in a known state can address safety or security in accordance with the mission needs of the organization. Failure to a known secure state helps prevent a loss of confidentiality, integrity, or availability in the event of a failure of the information system or a component of the system. Preserving network element state information helps to facilitate network element restart and return to the operational mode of the organization with less disruption to mission-essential processes.
Check Content
Verify that in the event of device failure, the Unified Communications Endpoint preserves any information necessary to determine cause of failure and return to operations with least disruption to service. If the Unified Communications Endpoint does not preserve any information necessary to determine cause of failure, this is a finding. If the Unified Communications Endpoint does not return to operations with least disruption to service after device failure, this is a finding.
Fix Text
Configure the Unified Communications Endpoint, in the event of device failure, to preserve any information necessary to determine cause of failure. Also configure the Unified Communications Endpoint to return to operations with least disruption to service.
Additional Identifiers
Rule ID: SRG-NET-000236-VVEP-00043_rule
Vulnerability ID: SRG-NET-000236-VVEP-00043
Group Title: SRG-NET-000236-VVEP-00043
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001665 |
Preserve organization-defined system state information in the event of a system failure. |
Controls
Number | Title |
---|---|
SC-24 |
Fail in Known State |