SV-21739r1_rule
V-19598
Deficient design: NIDS protection for VVoIP
VVoIP 6125 (DISN-IPVS)
CAT II
10
In the event the VVoIP system within the enclave is interconnected with other VVoIP systems across the WAN, ensure the required internal Network IDS (NIDS) is implemented such that it monitors the traffic to/from both the data firewall (function) and the required VVoIP firewall/EBC (function).
NOTE: This is applicable whether the VVoIP system is integrated with the DISN IPVS or not.
Inspect the configurations and connections of the NIDS and the network elements to which it is (they are) connected to determine compliance with the requirement. Determine if the traffic to/from the VVoIP firewall is in deed monitored by the (or a) NIDS.
V-19598
False
VVoIP 6125 (DISN-IPVS)
Inspect the configurations and connections of the NIDS and the network elements to which it is (they are) connected to determine compliance with the requirement. Determine if the traffic to/from the VVoIP firewall is in deed monitored by the (or a) NIDS.
M
Unauthorized and undetected access or compromise of the enclave or the services it supports
Information Assurance Officer
594