Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-16107 | VVoIP 1125 | SV-17095r2_rule | Medium |
Description |
---|
It is important that UC soft clients be tested and subsequently certified and accredited for IA purposes, to include upgrades or patches. Applications that have not been sufficiently vetted may introduce malware to the network or have security issues an adversary may manipulate. |
STIG | Date |
---|---|
Voice Video Services Policy Security Technical Implementation Guide | 2019-01-09 |
Check Text ( C-17151r3_chk ) |
---|
Review the site documentation to confirm UC soft clients are tested and approved prior to implementation. If the confirm UC soft clients are not tested and approved prior to implementation, this is a finding. |
Fix Text (F-16212r2_fix) |
---|
Ensure UC soft clients are tested and approved prior to implementation. |