Check: VVoIP 1040
Voice Video Services Policy STIG:
VVoIP 1040
(in versions v3 r18 through v3 r15)
Title
The voicemail system and/or server must implement applicable SRG and/or STIG guidance. (Cat III impact)
Discussion
Voice mail services are subject to the guidance and requirements in the Voice VIdeo STIGs. Older voice mail systems/servers commonly use proprietary Oss, while newer ones often run on Windows or Linux. The Defense Switched Network (DSN) STIG has been sunsetted. It is available on IASE in the Sunset Products page for telecommunications to be used for reference (https://iase.disa.mil/stigs/sunset/telecomm/Pages/index.aspx). The Voice Video Services Policy STIG, VVoIP STIG, Voice Video Endpoint SRG, and Voice Video Session Mgmt SRG contain the current guidance the DSN STIG covered. Additionally, the underlying OS, any attached database, and any applications providing ancillary functions must be assessed using the most appropriate guidance SRGs/STIGs.
Check Content
Review the site documentation to confirm all voicemail systems and servers implement the appropriate SRGs and STIGs. The server OS must be assessed using the Windows, Linux, or other appropriate STIG. The application and supporting services must be assessed using the appropriate (e.g., application, web server, database) SRGs and STIGs. If the voicemail systems and servers are not assessed using the appropriate SRGs and STIGs, this is a finding.
Fix Text
Ensure voicemail systems and servers are secured using the appropriate (e.g., application, web server, database, OS) SRGs and STIGs.
Additional Identifiers
Rule ID: SV-8739r2_rule
Vulnerability ID: V-8253
Group Title: VVoIP 1040
Expert Comments
CCIs
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Number | Title |
---|---|
No controls are assigned to this check |