Check: SRG-NET-000015-VVEP-00013
Voice Video Endpoint SRG:
SRG-NET-000015-VVEP-00013
(in versions v2 r2 through v1 r4)
Title
The Voice Video Endpoint must register with a Voice Video Session Manager. (Cat I impact)
Discussion
Authentication must not automatically give an entity access to an asset. Authorization procedures and controls must be implemented to ensure each authenticated entity also has a validated and current authorization. Authorization is the process of determining whether an entity, once authenticated, is permitted to access a specific asset. Registration authenticates and authorizes endpoints with the Voice Video Session Manager. For most VoIP systems, registration is the process of centrally recording the user ID, endpoint MAC address, service/policy profile with 2 stage authentication prior to authorizing the establishment of the session and user service. The event of successful registration creates the session record immediately. VC systems register using a similar process with a gatekeeper. Without enforcing registration, an adversary could impersonate a legitimate device on the Voice Video network.
Check Content
Verify the Voice Video Endpoint registers with a Voice Video Session Manager. If the Voice Video Endpoint does not registers with a Voice Video Session Manager, this is a finding.
Fix Text
Configure the Voice Video Endpoint to register with a Voice Video Session Manager.
Additional Identifiers
Rule ID: SV-206746r604140_rule
Vulnerability ID: V-206746
Group Title: SRG-NET-000015
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000213 |
The information system enforces approved authorizations for logical access to information and system resources in accordance with applicable access control policies. |
Controls
Number | Title |
---|---|
AC-3 |
Access Enforcement |