UCF STIG Viewer Logo

The Direct Inward System Access feature and/or access to Voice Mail is not controlled by either class of service, special authorization code, or PIN.


Overview

Finding ID Version Rule ID IA Controls Severity
V-7941 DSN07.01 SV-8427r1_rule ECSC-1 Low
Description
Requirement: The IAO will ensure that either class of service, special authorization code or PIN controls access to Voice Mail services. If used, the Direct Inward System Access feature provides subscriber access to the DSN from outside facilities. Users of this feature may connect to the DSN switch from the trunk side of the system and appear to the system as a local user having access to system features. Such users can make calls on the DSN as if they are on the line side of the switch. If this feature is not controlled, risk of unauthorized access to the DSN could result in call fraud and abuse. If operationally required, this feature should be implemented with class of service, special authorization code, or PIN assigned. Additionally. Voice Mail access should be configured to require a PIN.
STIG Date
Defense Switched Network (DSN) STIG 2017-01-19

Details

Check Text ( C-7374r1_chk )
Review current configuration files of effected devices to confirm compliance
Fix Text (F-7968r1_fix)
Implement processes / procedures, generate documents, and/or adjust configuration(s) / architecture, as necessary to comply with policy.