STIGQter STIGQter: STIG Summary: Video Services Policy STIG Version: 1 Release: 11 Benchmark Date: 24 Apr 2020:

VTU encryption indicator is not enabled.

DISA Rule

SV-18859r1_rule

Vulnerability Number

V-17685

Group Title

RTS-VTC 1250.00 [IP][ISDN]

Rule Version

RTS-VTC 1250.00

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

[IP][ISDN]; Perform the following tasks:

Implement VTU CODECs that provide an on screen indicator that encryption is occurring and active.
OR
If the encryption is provided by external devices (not the CODEC), implement an external indicator to display encryption status in place of an on-screen indicator provided by the CODEC.

Check Contents

[IP][ISDN]; Interview the IAO to validate compliance with the following requirement:

Ensure all VTU’s under IAO’s control display a visual indicator that encryption is in fact taking place.

Note: During APL testing, this is a finding in the event this requirement is not supported by the CODEC i.e., an on screen visual indicator displaying that encryption is indeed occurring.

Note: In the event encryption is provided by external devices (not the CODEC), an external indicator meets this requirement in place of the on-screen indicator.

Vulnerability Number

V-17685

Documentable

False

Rule Version

RTS-VTC 1250.00

Severity Override Guidance

[IP][ISDN]; Interview the IAO to validate compliance with the following requirement:

Ensure all VTU’s under IAO’s control display a visual indicator that encryption is in fact taking place.

Note: During APL testing, this is a finding in the event this requirement is not supported by the CODEC i.e., an on screen visual indicator displaying that encryption is indeed occurring.

Note: In the event encryption is provided by external devices (not the CODEC), an external indicator meets this requirement in place of the on-screen indicator.

Check Content Reference

I

Potential Impact

The inadvertent disclosure of sensitive or classified information to a caller of a VTU that may not have an appropriate need-to-know or proper security clearance.

Responsibility

Information Assurance Officer

Target Key

1418

Comments