Check: SRG-NET-000273-VVSM-00101
Unified Communications Session Management SRG:
SRG-NET-000273-VVSM-00101
(in version v1 r0.1)
Title
The Unified Communications Session Manager must be configured to generate session (call) records that provide information necessary for corrective actions without revealing personally identifiable information or sensitive information. (Cat II impact)
Discussion
Any Unified Communications Session Manager providing too much information in session records risks compromising the data and security of the application and system. The structure and content of session records must be carefully considered by the organization and development team.
Check Content
Verify the Unified Communications Session Manager generates session records that provide information necessary for corrective actions without revealing personally identifiable information or sensitive information. If the Unified Communications Session Manager does not generate session records that provide information necessary for corrective actions without revealing personally identifiable information or sensitive information, this is a finding.
Fix Text
Configure the Unified Communications Session Manager to generate session records that provide information necessary for corrective actions without revealing personally identifiable information or sensitive information.
Additional Identifiers
Rule ID: SRG-NET-000273-VVSM-00101_rule
Vulnerability ID: SRG-NET-000273-VVSM-00101
Group Title: SRG-NET-000273-VVSM-00101
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001312 |
Generate error messages that provide information necessary for corrective actions without revealing information that could be exploited. |
Controls
Number | Title |
---|---|
SI-11 |
Error Handling |