Check: VVoIP 1021 (GENERAL)
Voice Video Services Policy STIG:
VVoIP 1021 (GENERAL)
(in versions v3 r18 through v3 r15)
Title
Unnecessary PPS have not been disabled or removed from VVoIP system devices or servers. (Cat II impact)
Discussion
The availability of applications and services that are not necessary for the OAM&P of the VVoIP system’s devices and servers, running or not as well as the existence of their code, places them at risk of being attacked and these avenues exploited. As such they should be removed if possible or minimally disabled so they cannot run and be exploited. For VVoIP and UC servers and endpoints, remove the software for or minimally disable PPS that are not necessary for the operation or maintenance of the system. Limit production PPS to production interfaces and management PPS to the OAM&P interfaces.
Check Content
Interview the IAO to validate compliance with the following requirement: For VVoIP and UC servers and endpoints, ensure all PPS that are not necessary for the operation or maintenance of the system are disabled or the supporting software removed. Limit production PPS to production interfaces and management PPS to the OAM&P interfaces.
Fix Text
Disable all PPS on all VVoIP or UC system servers and sevices that are not required to support OAM&P in the specific VVoIP system implementation. Additionally, if possible, remove the software for the unnecessary PPS.
Additional Identifiers
Rule ID: SV-23733r1_rule
Vulnerability ID: V-21521
Group Title: Deficient Security: Unnecessary PPS disablement
Expert Comments
CCIs
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Number | Title |
---|---|
No controls are assigned to this check |