Check: SRG-NET-000015-VVSM-00001
Voice Video Session Management SRG:
SRG-NET-000015-VVSM-00001
(in versions v2 r2 through v1 r5)
Title
The Voice Video Session Manager must enforce registration of only approved Voice Video endpoints prior to operation. (Cat I impact)
Discussion
Authentication must not automatically give an entity access to an asset. Authorization procedures and controls must be implemented to ensure each authenticated entity also has a validated and current authorization. Authorization is the process of determining whether an entity, once authenticated, is permitted to access a specific asset. Registration authenticates and authorizes endpoints with the Voice Video Session Manager. For most VoIP systems, registration is the process of centrally recording the user ID, endpoint MAC address, service/policy profile with 2 stage authentication prior to authorizing the establishment of the session and user service. The event of successful registration creates the session record immediately. VC systems register using a similar process with a gatekeeper. Without enforcing registration, an adversary could impersonate a legitimate device on the Voice Video network.
Check Content
Verify the Voice Video Session Manager enforces registration of only approved Voice Video endpoints prior to the endpoints operating with the system. If the Voice Video Session Manager permits registration of unapproved Voice Video endpoints prior to operation, this is a finding.
Fix Text
Configure the Voice Video Session Manager to enforce registration of only approved Voice Video endpoints prior to operating with the system.
Additional Identifiers
Rule ID: SV-206811r508661_rule
Vulnerability ID: V-206811
Group Title: SRG-NET-000015
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000213 |
The information system enforces approved authorizations for logical access to information and system resources in accordance with applicable access control policies. |
Controls
Number | Title |
---|---|
AC-3 |
Access Enforcement |