STIGQter STIGQter: STIG Summary: Voice Video Services Policy Security Technical Implementation Guide Version: 3 Release: 17 Benchmark Date: 25 Oct 2019:

Regular documented testing of hardware based COOP/backup or emergency telephones is not performed in accordance with a documented test plan or related documentation is deficient or non existent.

DISA Rule

SV-23715r1_rule

Vulnerability Number

V-21506

Group Title

Deficient testing: COOP/Emergency phones

Rule Version

VVoIP 1921 (GENERAL)

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

In the event hardware based instruments are implemented in a COOP capacity for backup or emergency communications, and such instruments are not regularly used, the IAO will ensure the functionality of these instruments by implementing and documenting a testing program which will include the documentation of the results of each test.

NOTE: The frequency of testing for each instrument is variable but should minimally be monthly. Weekly, daily, or randomly within a monthly cycle is better. Testing may be made the responsibility of the user(s) the instrument serves providing they document their tests. The test could minimally involve determining if dial tone is present (unless generated within the phone as with some VoIP phones), but should include the placement of a call to an emergency number.

Check Contents

Inspect the documented test plan that ensures COOP/ backup or emergency instrument functionality. Inspect the documented test results. This is a finding if the documentation does not exist or if the tests are not conducted in accordance with the plan.

Vulnerability Number

V-21506

Documentable

False

Rule Version

VVoIP 1921 (GENERAL)

Severity Override Guidance

Inspect the documented test plan that ensures COOP/ backup or emergency instrument functionality. Inspect the documented test results. This is a finding if the documentation does not exist or if the tests are not conducted in accordance with the plan.

Check Content Reference

M

Potential Impact

The inability to make an emergency or any call in the event the COOP/backup/emergency telephone is nonfunctional.

Responsibility

Information Assurance Officer

Target Key

594

Comments