The Enterprise Voice, Video, and Messaging Session Manager must be configured to use an organizational-level user account management system.
An XCCDF Rule
Description
<VulnDiscussion>To effectively manage user accounts, organizational level systems such as Lightweight Directory Access Protocol (LDAP) or Active Directory (AD) are used to create and manage user credentials that can be used across the organization. This reduces the need for separate user account databases across systems, that can create orphaned account issues, and the need to remember different credentials for each system. When user access is no longer authorized, an organizational level system can simultaneously revoke access to all systems.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>
- ID
- SV-260010r948991_rule
- Severity
- High
- References
- Updated
Remediation - Manual Procedure
Configure the Enterprise Voice, Video, and Messaging Session Manager to use an organizational level user account management system.