UCF STIG Viewer Logo

The Voice Video Endpoint must register with a Voice Video Session Manager.


Overview

Finding ID Version Rule ID IA Controls Severity
V-206746 SRG-NET-000015-VVEP-00013 SV-206746r604140_rule High
Description
Authentication must not automatically give an entity access to an asset. Authorization procedures and controls must be implemented to ensure each authenticated entity also has a validated and current authorization. Authorization is the process of determining whether an entity, once authenticated, is permitted to access a specific asset. Registration authenticates and authorizes endpoints with the Voice Video Session Manager. For most VoIP systems, registration is the process of centrally recording the user ID, endpoint MAC address, service/policy profile with 2 stage authentication prior to authorizing the establishment of the session and user service. The event of successful registration creates the session record immediately. VC systems register using a similar process with a gatekeeper. Without enforcing registration, an adversary could impersonate a legitimate device on the Voice Video network.
STIG Date
Voice Video Endpoint Security Requirements Guide 2020-12-04

Details

Check Text ( C-7002r363761_chk )
Verify the Voice Video Endpoint registers with a Voice Video Session Manager.

If the Voice Video Endpoint does not registers with a Voice Video Session Manager, this is a finding.
Fix Text (F-7002r363762_fix)
Configure the Voice Video Endpoint to register with a Voice Video Session Manager.