STIGQter STIGQter: STIG Summary: Video Services Policy STIG Version: 1 Release: 11 Benchmark Date: 24 Apr 2020:

The Videoconferencing system and components passwords must meet complexity and strength policy.

DISA Rule

SV-18863r4_rule

Vulnerability Number

V-17689

Group Title

RTS-VTC 2024

Rule Version

RTS-VTC 2024.00

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Implement videoconferencing system and components passwords to meet complexity and strength policy.

Check Contents

Review site documentation to confirm a policy and procedure requires the videoconferencing system and components to have passwords meeting complexity or strength policy, as follows:
- PINs entered into a local video endpoint from a hand-held remote control must contain at least six digits.
- PINs entered into a remote video endpoint from a hand-held remote control must contain at least nine digits.
- Passwords entered from a keyboard must contain at least at least 15 characters with at least one lowercase letter, one uppercase letter, one number, and one special character.
- Passwords and PINs must be encrypted per DoD standards.

If the videoconferencing system and components do not have passwords meeting complexity or strength policy, this is a finding.

Vulnerability Number

V-17689

Documentable

False

Rule Version

RTS-VTC 2024.00

Severity Override Guidance

Review site documentation to confirm a policy and procedure requires the videoconferencing system and components to have passwords meeting complexity or strength policy, as follows:
- PINs entered into a local video endpoint from a hand-held remote control must contain at least six digits.
- PINs entered into a remote video endpoint from a hand-held remote control must contain at least nine digits.
- Passwords entered from a keyboard must contain at least at least 15 characters with at least one lowercase letter, one uppercase letter, one number, and one special character.
- Passwords and PINs must be encrypted per DoD standards.

If the videoconferencing system and components do not have passwords meeting complexity or strength policy, this is a finding.

Check Content Reference

M

Responsibility

Other

Target Key

1418

Comments