Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-43016 | RTS-VTC 7020 | SV-55745r1_rule | EBCR-1 ECIC-1 | High |
Description |
---|
Connecting to networks of different classifications simultaneously incurs the risk of data from a higher classification being released to a network of a lower classification, referred to as a “spill”. It is imperative that networks of differing classification levels or with differing handling caveats not be interconnected at any time. Separation in a multinetwork VTC system is maintained by the use of an A/B, A/B/C, or A/B/C/D switch that meets requirements for channel isolation, or by manual connection of the CODEC to one network at a time. |
STIG | Date |
---|---|
Video Services Policy STIG | 2015-02-05 |
Check Text ( C-49173r4_chk ) |
---|
Review the VTC system architecture to verify that an approved A/B, A/B/C, or A/B/C/D switch is present and properly cabled. Alternately, validate that the VTC CODEC is manually connected to one network at a time through the use of a single patch cord. If neither is in place, this is a finding. |
Fix Text (F-48600r3_fix) |
---|
Obtain and install an approved A/B, A/B/C, or A/B/C/D switch. Alternately, manually connect the VTC CODEC to one network at a time through the use of a single patch cord. |