Check: SRG-NET-000352-VVEP-00038
Voice Video Endpoint SRG:
SRG-NET-000352-VVEP-00038
(in versions v2 r2 through v1 r4)
Title
The Voice Video Endpoint processing classified information over public networks must implement NSA-approved cryptography. (Cat I impact)
Discussion
Use of weak or untested encryption algorithms undermines the purposes of utilizing encryption to protect data. The network element must implement cryptographic modules adhering to the higher standards approved by the federal government since this provides assurance they have been tested and validated.
Check Content
Verify the Voice Video Endpoint processing classified information over public networks implements NSA-approved cryptography. If the Voice Video Endpoint processing classified information over public networks does not implement NSA-approved cryptography, this is a finding.
Fix Text
Configure the Voice Video Endpoint processing classified information over public networks to implement NSA-approved cryptography.
Additional Identifiers
Rule ID: SV-206775r604140_rule
Vulnerability ID: V-206775
Group Title: SRG-NET-000352
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-002450 |
The information system implements organization-defined cryptographic uses and type of cryptography required for each use in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, and standards. |
Controls
Number | Title |
---|---|
SC-13 |
Cryptographic Protection |