Skip to content

Enterprise Voice, Video, and Messaging Endpoint Security Requirements Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • SRG-NET-000018

    <GroupDescription></GroupDescription>
    Group
  • The Enterprise Voice, Video, and Messaging Endpoint not supporting 802.1x must be configured to use MAC Authentication Bypass (MAB) on the access switchport.

    &lt;VulnDiscussion&gt;IEEE 802.1x is a protocol used to control access to LAN services via a network access switchport or wireless access point tha...
    Rule Medium Severity
  • SRG-NET-000018

    <GroupDescription></GroupDescription>
    Group
  • The Enterprise Voice, Video, and Messaging Endpoint must be configured to use a voice video VLAN, separate from all other VLANs.

    &lt;VulnDiscussion&gt;Virtualized networking is used to separate voice video traffic from other types of traffic, such as data, management, and oth...
    Rule Medium Severity
  • SRG-NET-000018

    <GroupDescription></GroupDescription>
    Group
  • The Enterprise Voice, Video, and Messaging Endpoint must be configured to disable the Far End Camera Control feature if supported.

    &lt;VulnDiscussion&gt;Many VTC endpoints support Far End Camera Control (FECC). This feature uses H.281 protocol, which must be supported by both V...
    Rule Medium Severity
  • SRG-NET-000029

    <GroupDescription></GroupDescription>
    Group
  • The Enterprise Voice, Video, and Messaging Endpoint must notify the user, upon successful logon (access), of the number of unsuccessful logon (access) attempts since the last successful logon (access).

    &lt;VulnDiscussion&gt;Users need to be aware of activity that occurs regarding their account. Providing users with information regarding the number...
    Rule Medium Severity
  • SRG-NET-000053

    <GroupDescription></GroupDescription>
    Group
  • The Enterprise Voice, Video, and Messaging Endpoint must be configured to apply 802.1Q VLAN tags to signaling and media traffic.

    &lt;VulnDiscussion&gt;When Enterprise Voice, Video, and Messaging Endpoints do not dynamically assign 802.1Q VLAN tags as data is created and combi...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules