Check: VVoIP 1130
Voice Video Services Policy STIG:
VVoIP 1130
(in versions v3 r18 through v3 r15)
Title
Unified Capabilities (UC) soft client patches and upgrades must be tested and approved prior to implementation. (Cat II impact)
Discussion
It is important that UC soft clients be tested and subsequently certified and accredited for IA purposes, to include upgrades or patches. Applications that have not been sufficiently vetted may introduce malware to the network or have security issues an adversary may manipulate.
Check Content
Review the site documentation to confirm the UC soft client patches and upgrades are tested and approved prior to implementation. If the UC soft client patches and upgrades are not tested and approved prior to implementation, this is a finding.
Fix Text
Ensure UC soft client patches and upgrades are tested and approved prior to implementation.
Additional Identifiers
Rule ID: SV-17096r2_rule
Vulnerability ID: V-16108
Group Title: VVoIP 1130
Expert Comments
CCIs
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Number | Title |
---|---|
No controls are assigned to this check |