Check: SRG-NET-000138-VVEP-00029
Voice Video Endpoint SRG:
SRG-NET-000138-VVEP-00029
(in versions v2 r2 through v1 r4)
Title
The Voice Video Endpoint used for videoconferencing must uniquely identify participating users. (Cat I impact)
Discussion
To assure accountability and prevent unauthenticated access, users must be identified to prevent potential misuse and compromise of the system. The Voice Video Endpoint must display the source of an incoming call and the participant's identity to aid the user in deciding whether to answer a call. The information potentially at risk is that which can be seen in the physical area of the Voice Video Endpoint or carried by the conference in which it is participating. This does not apply to authentication for the purpose of configuring the device itself (i.e., device management).
Check Content
Verify the Voice Video Endpoint used for videoconferencing uniquely identifies participating users. Identification must be visible and displayed locally. If the Voice Video Endpoint used for videoconferencing does not uniquely identify participating users, this is a finding.
Fix Text
Configure the Voice Video Endpoint used for videoconferencing to uniquely identify participating users.
Additional Identifiers
Rule ID: SV-206761r604140_rule
Vulnerability ID: V-206761
Group Title: SRG-NET-000138
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000764 |
The information system uniquely identifies and authenticates organizational users (or processes acting on behalf of organizational users). |
Controls
Number | Title |
---|---|
IA-2 |
Identification And Authentication (Organizational Users) |