Skip to content

I - Mission Critical Sensitive

Rules and Groups employed by this XCCDF Profile

  • SRG-NET-000015

    <GroupDescription></GroupDescription>
    Group
  • The Enterprise Voice, Video, and Messaging Endpoint must be configured to prevent the configuration or display of configuration settings without the use of a PIN or password.

    &lt;VulnDiscussion&gt;Many Enterprise Voice, Video, and Messaging Endpoints can set or display configuration settings in the instrument itself. Thi...
    Rule Medium Severity
  • SRG-NET-000015

    <GroupDescription></GroupDescription>
    Group
  • The Enterprise Voice, Video, and Messaging Endpoint must be configured to register with an Enterprise Voice, Video, and Messaging Session Manager.

    &lt;VulnDiscussion&gt;For most VoIP systems, registration is the process of centrally recording the user ID, endpoint MAC address, service/policy p...
    Rule High Severity
  • SRG-NET-000018

    <GroupDescription></GroupDescription>
    Group
  • The Enterprise Voice, Video, and Messaging Endpoint PC port must be configured to maintain VLAN separation from the voice video VLAN, or be disabled.

    &lt;VulnDiscussion&gt;Virtualized networking is used to separate voice video traffic from other types of traffic, such as data, management, and oth...
    Rule Medium Severity
  • SRG-NET-000018

    <GroupDescription></GroupDescription>
    Group
  • The Enterprise Voice, Video, and Messaging Endpoint must be configured to integrate into the implemented 802.1x network access control system.

    &lt;VulnDiscussion&gt;IEEE 802.1x is a protocol used to control access to LAN services via a network access switchport or wireless access point tha...
    Rule Medium Severity
  • SRG-NET-000018

    <GroupDescription></GroupDescription>
    Group
  • The Enterprise Voice, Video, and Messaging Endpoint PC port must be configured to connect to an 802.1x supplicant or the PC port must be disabled.

    &lt;VulnDiscussion&gt;IEEE 802.1x is a protocol used to control access to LAN services via a network access switchport or wireless access point tha...
    Rule Medium Severity
  • SRG-NET-000018

    <GroupDescription></GroupDescription>
    Group
  • The Enterprise Voice, Video, and Messaging Endpoint not supporting 802.1x must be configured to use MAC Authentication Bypass (MAB) on the access switchport.

    &lt;VulnDiscussion&gt;IEEE 802.1x is a protocol used to control access to LAN services via a network access switchport or wireless access point tha...
    Rule Medium Severity
  • SRG-NET-000018

    <GroupDescription></GroupDescription>
    Group
  • The Enterprise Voice, Video, and Messaging Endpoint must be configured to use a voice video VLAN, separate from all other VLANs.

    &lt;VulnDiscussion&gt;Virtualized networking is used to separate voice video traffic from other types of traffic, such as data, management, and oth...
    Rule Medium Severity
  • SRG-NET-000018

    <GroupDescription></GroupDescription>
    Group
  • The Enterprise Voice, Video, and Messaging Endpoint must be configured to disable the Far End Camera Control feature if supported.

    &lt;VulnDiscussion&gt;Many VTC endpoints support Far End Camera Control (FECC). This feature uses H.281 protocol, which must be supported by both V...
    Rule Medium Severity
  • SRG-NET-000029

    <GroupDescription></GroupDescription>
    Group
  • The Enterprise Voice, Video, and Messaging Endpoint must be configured to apply 802.1Q VLAN tags to signaling and media traffic.

    &lt;VulnDiscussion&gt;When Enterprise Voice, Video, and Messaging Endpoints do not dynamically assign 802.1Q VLAN tags as data is created and combi...
    Rule Medium Severity
  • SRG-NET-000041

    <GroupDescription></GroupDescription>
    Group
  • The Enterprise Voice, Video, and Messaging Endpoint must be configured to display the Standard Mandatory DOD Notice and Consent Banner before granting access to the network.

    &lt;VulnDiscussion&gt;Display of a standardized and approved use notification before granting access to the network ensures privacy and security no...
    Rule Medium Severity
  • SRG-NET-000042

    <GroupDescription></GroupDescription>
    Group
  • The Enterprise Voice, Video, and Messaging Endpoint must be configured to retain the Standard Mandatory DOD Notice and Consent Banner on the screen until users acknowledge the usage conditions and take explicit actions to log on for further access.

    &lt;VulnDiscussion&gt;The banner must be acknowledged by the user prior to allowing the user access to the network. This provides assurance that th...
    Rule Medium Severity
  • SRG-NET-000048

    <GroupDescription></GroupDescription>
    Group
  • The Enterprise Voice, Video, and Messaging Endpoint must notify the user, upon successful logon (access) to the network element, of the date and time of the last logon (access).

    &lt;VulnDiscussion&gt;Users need to be aware of activity that occurs regarding their account. Providing users with information regarding the date a...
    Rule Medium Severity
  • SRG-NET-000049

    <GroupDescription></GroupDescription>
    Group
  • The Enterprise Voice, Video, and Messaging Endpoint must notify the user, upon successful logon (access), of the number of unsuccessful logon (access) attempts since the last successful logon (access).

    &lt;VulnDiscussion&gt;Users need to be aware of activity that occurs regarding their account. Providing users with information regarding the number...
    Rule Medium Severity
  • SRG-NET-000053

    <GroupDescription></GroupDescription>
    Group
  • The Enterprise Voice, Video, and Messaging Endpoint must be configured to limit the number of concurrent sessions to an organizationally defined number.

    &lt;VulnDiscussion&gt;Enterprise Voice, Video, and Messaging Endpoint management includes the ability to control the number of user sessions and li...
    Rule Medium Severity
  • SRG-NET-000074

    <GroupDescription></GroupDescription>
    Group
  • The Enterprise Voice, Video, and Messaging Endpoint must be configured to produce session (call detail) records containing what type of connection occurred.

    &lt;VulnDiscussion&gt;Session records are commonly produced by session management and border elements. Many Enterprise Voice, Video, and Messaging ...
    Rule Medium Severity
  • SRG-NET-000075

    <GroupDescription></GroupDescription>
    Group
  • The Enterprise Voice, Video, and Messaging Endpoint must be configured to produce session (call detail) records containing when (date and time) the connection occurred.

    &lt;VulnDiscussion&gt;Session records are commonly produced by session management and border elements. Many Enterprise Voice, Video, and Messaging ...
    Rule Medium Severity
  • SRG-NET-000076

    <GroupDescription></GroupDescription>
    Group
  • The Enterprise Voice, Video, and Messaging Endpoint must be configured to produce session (call detail) records containing where the connection occurred.

    &lt;VulnDiscussion&gt;Session records are commonly produced by session management and border elements. Many Enterprise Voice, Video, and Messaging ...
    Rule Medium Severity
  • SRG-NET-000077

    <GroupDescription></GroupDescription>
    Group
  • The Enterprise Voice, Video, and Messaging Endpoint must be configured to produce session (call detail) records containing the source of the connection.

    &lt;VulnDiscussion&gt;Session records are commonly produced by session management and border elements. Many Enterprise Voice, Video, and Messaging ...
    Rule Medium Severity
  • SRG-NET-000078

    <GroupDescription></GroupDescription>
    Group
  • The Enterprise Voice, Video, and Messaging Endpoint must be configured to produce session (call detail) records containing the outcome of the connection.

    &lt;VulnDiscussion&gt;Session records are commonly produced by session management and border elements. Many Enterprise Voice, Video, and Messaging ...
    Rule Medium Severity
  • SRG-NET-000079

    <GroupDescription></GroupDescription>
    Group
  • The Enterprise Voice, Video, and Messaging Endpoint must be configured to produce session (call detail) records containing the identity of all users.

    &lt;VulnDiscussion&gt;Without information that establishes the identity of the subjects (i.e., users or processes acting on behalf of users) associ...
    Rule Medium Severity
  • SRG-NET-000113

    <GroupDescription></GroupDescription>
    Group
  • The Enterprise Voice, Video, and Messaging Endpoint must be configured to provide session (call detail) record generation capability.

    &lt;VulnDiscussion&gt;Session records are commonly produced by session management and border elements. Many Enterprise Voice, Video, and Messaging ...
    Rule Medium Severity
  • SRG-NET-000131

    <GroupDescription></GroupDescription>
    Group
  • The Enterprise Voice, Video, and Messaging Endpoint must be configured to disable or remove nonessential capabilities.

    &lt;VulnDiscussion&gt;It is detrimental for Enterprise Voice, Video, and Messaging Endpoints when unnecessary features are enabled by default. Ofte...
    Rule Medium Severity
  • SRG-NET-000132

    <GroupDescription></GroupDescription>
    Group
  • The Enterprise Voice, Video, and Messaging Endpoint must be configured to only use ports, protocols, and services allowed per the Ports, Protocols, and Services Management (PPSM) Category Assurance List (CAL) and Vulnerability Assessments (VAs).

    &lt;VulnDiscussion&gt;In order to prevent unauthorized connection of devices, unauthorized transfer of information, or unauthorized tunneling (i.e....
    Rule High Severity
  • SRG-NET-000138

    <GroupDescription></GroupDescription>
    Group
  • The Enterprise Voice, Video, and Messaging Endpoint must be configured to uniquely identify participating users.

    &lt;VulnDiscussion&gt;To ensure accountability and prevent unauthenticated access, users must be identified to prevent potential misuse and comprom...
    Rule High Severity
  • SRG-NET-000140

    <GroupDescription></GroupDescription>
    Group
  • The Enterprise Voice, Video, and Messaging Endpoint must use multifactor authentication for network access to nonprivileged (nonadmin) accounts.

    &lt;VulnDiscussion&gt;To ensure accountability and prevent unauthenticated access, nonprivileged users must use multifactor authentication to preve...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules