From Voice Video Policy Security Technical Implementation Guide
Part of SRG-POL-300042
Associated with: CCI-002163
During Voice Video endpoint registration with the session controller, a file containing specific configuration settings is downloaded by the endpoint from the session manager. This file contains the phone number assigned to the endpoint, the IP addresses for session management, the software menus specific to the system, the endpoint configuration password, the stored personal preferences and speed dial numbers, and other system operational information. These configuration settings can be updated by resetting and re-registering the endpoint, which causes an updated configuration file to be downloaded.
Review the procedures to facilitate organization-specific Voice Video access control policy and associated access controls. Verify the procedures of the Voice Video access control policy for the configuration and display of endpoint password/PIN are documented and enforced. Confirm that Voice Video endpoint password/PIN settings meet DoD password policies for length, complexity, expiration, change intervals, and other conditions to change configuration of the endpoint. If the organization does not document and enforce procedures of the Voice Video access control policy for the configuration and display of endpoint password/PIN, this is a finding.
Develop and document procedures implementing the Voice Video access control policy for the configuration and display of endpoint password/PIN. The procedures must meet DoD password policies for length, complexity, expiration, change intervals, and other conditions as determined by local authority. NOTE: Most instruments will only accept numerical input; therefore, a PIN is used. Some instruments may accept alpha characters for passwords. These factors help determine the password/PIN complexity that is achievable.
	Lavender hyperlinks in small type off to the right (of CSS
	class id, if you view the page source) point to
	globally unique URIs for each document and item. Copy the
	link location and paste anywhere you need to talk
	unambiguously about these things.
	
      
	You can obtain data about documents and items in other
	formats. Simply provide an HTTP header Accept:
	text/turtle or
	Accept: application/rdf+xml.
      
Powered by sagemincer