STIGQter STIGQter: STIG Summary: Video Services Policy STIG Version: 1 Release: 11 Benchmark Date: 24 Apr 2020:

Inadequate notification to conference participants (manual or automatic) of monitoring activity by someone that is not a direct participant in a VTC session/conference.

DISA Rule

SV-18854r1_rule

Vulnerability Number

V-17680

Group Title

RTS-VTC 1164.00 [IP][ISDN]

Rule Version

RTS-VTC 1164.00

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

[IP][ISDN]; Perform the following tasks:
- Configure the CODEC and/or MCU to automatically display an indication on all endpoints participating in a conference that the conference is being monitored.
OR
- Develop a SOP that addresses manual notification by SAs and chair persons that the conference is being monitored.

Check Contents

[IP][ISDN]; Interview the IAO to validate compliance with the following requirement:

Ensure conference participants are made aware that a conference is being monitored by someone that is not a direct participant of the call or conference.

Interview the IAO to determine if this requirement is covered by an automatic indicator that appears on all participating endpoints OR is covered in a SOP and user training/agreements. Interview the IAO and monitoring “operator/facilitator” to determine their awareness and implementation of the requirement.

Vulnerability Number

V-17680

Documentable

False

Rule Version

RTS-VTC 1164.00

Severity Override Guidance

[IP][ISDN]; Interview the IAO to validate compliance with the following requirement:

Ensure conference participants are made aware that a conference is being monitored by someone that is not a direct participant of the call or conference.

Interview the IAO to determine if this requirement is covered by an automatic indicator that appears on all participating endpoints OR is covered in a SOP and user training/agreements. Interview the IAO and monitoring “operator/facilitator” to determine their awareness and implementation of the requirement.

Check Content Reference

I

Potential Impact

The inadvertent disclosure of sensitive or classified information to a SA that is monitoring a VTU that may not have an appropriate need-to-know or proper security clearance.

Responsibility

Information Assurance Officer

Target Key

1418

Comments