Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-79055 | SRG-NET-000041-VVEP-00064 | SV-93761r1_rule | Medium |
Description |
---|
Display of a standardized and approved use notification before granting access to the network ensures privacy and security notification verbiage used is consistent with applicable federal laws, Executive Orders, directives, policies, regulations, standards, and guidance. Consent to monitoring stickers. |
STIG | Date |
---|---|
Voice Video Endpoint Security Requirements Guide | 2019-03-15 |
Check Text ( C-78643r2_chk ) |
---|
If the Voice Video Endpoint is not a hardware endpoint, this is Not Applicable. Verify the Voice Video Endpoint has a physical DD Form 2056 or other approved consent to monitoring sticker affixed. An acceptable alternative is for the Voice Video Endpoint to display a digital representation of the DD Form 2056 clearly visible when the device is not in use. If the Voice Video Endpoint does not have a physical DD Form 2056 or other approved consent to monitoring sticker affixed, or alternatively display a digital representation, this is a finding. Note: For classified endpoints, the top portion of the sticker (or digital rendering) which says “DO NOT DISCUSS CLASSIFIED INFORMATION” must be removed. |
Fix Text (F-85805r1_fix) |
---|
Prominently affix a DD Form 2056 or other approved consent to monitoring sticker to the Voice Video Endpoint. Alternatively, program the Voice Video Endpoint to clearly display the following text verbatim when the device is not in use: “DO NOT DISCUSS CLASSIFIED INFORMATION” “This telephone is subject to monitoring at all times. Use of this telephone constitutes consent to monitoring.” Note: For classified endpoints, the top portion of the sticker (or digital rendering) which says “DO NOT DISCUSS CLASSIFIED INFORMATION” must be removed. |