Check: SRG-NET-000512-VVEP-00103
Unified Communications Endpoint SRG:
SRG-NET-000512-VVEP-00103
(in version v1 r0.1)
Title
The Unified Communications Endpoint must be configured to disable any auto answer features. (Cat II impact)
Discussion
A Unified Communications Endpoint set to automatically answer a call with audio or video capabilities enabled risks transmitting information not intended for the caller. In the event a Unified Communications Endpoint automatically answered a call during a classified meeting or discussion, potentially sensitive or classified information could be transmitted. The auto-answer feature must not be activated by a user unless the feature is required to satisfy mission requirements.
Check Content
Verify the Unified Communications Endpoint is configured to disable any auto answer features. If the Unified Communications Endpoint is not configured to disable auto answer features, this is a finding.
Fix Text
Configure the Unified Communications Endpoint to disable auto answer features.
Additional Identifiers
Rule ID: SRG-NET-000512-VVEP-00103_rule
Vulnerability ID: SRG-NET-000512-VVEP-00103
Group Title: SRG-NET-000512-VVEP-00103
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000366 |
Implement the security configuration settings. |
Controls
Number | Title |
---|---|
CM-6 |
Configuration Settings |