SV-8741r1_rule
V-8255
Deficient security: Personal VM settings via web
VVoIP 1520 (GENERAL)
CAT II
10
Configure the voicemail system web access to personal settings in accordance with the applicable private web server requirements in the Web STIG/Checklist and ensure web interface is configured to use HTTPS/TLS.
Have the IAO or SA demonstrate the various methods of accessing a subscriber’s personal settings. Specifically ask if there is “web” access using a browser on the phone or a PC. If so, have the IAO or SA demonstrate the configuration settings that provide encryption for the access.
V-8255
False
VVoIP 1520 (GENERAL)
Have the IAO or SA demonstrate the various methods of accessing a subscriber’s personal settings. Specifically ask if there is “web” access using a browser on the phone or a PC. If so, have the IAO or SA demonstrate the configuration settings that provide encryption for the access.
M
Denial of Service and/or unauthorized access to network or voice system resources or services and the information they contain. Application of features and potential call redirection by unauthorized users.
Information Assurance Officer
594