Voice Video Endpoint SRG Version Comparison
Voice Video Endpoint Security Requirements Guide
Comparison
There are 9 differences between versions v1 r6 (Jan. 1, 0001) (the "left" version) and v2 r2 (July 27, 2022) (the "right" version).
Check SRG-NET-000366-VVEP-00100 was added to the benchmark in the "right" version.
This check's original form is available here.
Text Differences
Title
Voice Video Endpoint guidance being utilized must be supported by DISA.
Check Content
The Voice Video Endpoint SRG is no longer supported by DISA.
Discussion
Security flaws with software applications are discovered daily. Vendors are constantly updating and patching their products to address newly discovered security vulnerabilities. Organizations (including any contractor to the organization) are required to promptly install security-relevant software updates (e.g., patches, service packs, and hot fixes). Flaws discovered during security assessments, continuous monitoring, incident response activities, or information system error handling must also be addressed expeditiously. Organization-defined time periods for updating security-relevant software may vary based on a variety of factors including, for example, the security category of the information system or the criticality of the update (i.e., severity of the vulnerability related to the discovered flaw). The current Voice Video STIG Guidance will be sunset because technology advancements and best practices have outpaced the existing guidelines. DISA recognizes the current VOIP STIGs require updating and will be placing the VOIP guidance on the STIG sunset list until new VOIP guidance can be developed. Plans are currently underway to draft new guidance, in the interim period, the sunset VOIP guidance can be utilized to the extent possible, but it will not be updated.
Fix
Utilize vendor best practices and the sunset Voice Video Endpoint guidance to the extent possible.