The organization must develop and document procedures to facilitate the implementation of the Call Detail Record (CDR) policy and associated audit controls.

From Voice Video Policy Security Technical Implementation Guide

Part of SRG-POL-300137

Associated with: CCI-000120

VVSP-01-000026_rule The organization must develop and document procedures to facilitate the implementation of the Call Detail Record (CDR) policy and associated audit controls.

Vulnerability discussion

The audit and accountability procedures implement audit and accountability policy. Organizational procedures must reflect applicable NIST and STIG guidance by determining applicable STIGs and SRGs and identifying the applicable audit and accountability controls and procedures.Developing and documenting implementation procedures for the CDR policy and associated controls addressing session initiation, status, and participants, using common date and time elements, provides methods to perform traffic and forensic analysis of Voice Video communications.

Check content

Review the developed and documented procedures to facilitate the implementation of CDR policy and associated access controls. These procedures must address the CDR policy governing all Voice Video systems that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance, to include storage and retention of records. If procedures have not been developed and documented that facilitate the implementation of CDR policy and associated access controls, this is a finding.

Fix text

Develop and document procedures to facilitate the implementation of CDR policy and associated access controls. These procedures must address the CDR policy governing all Voice Video systems that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance, to include storage and retention of records.

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer