The organization must disseminate to the ISSO and ISSM and others, as the local organization deems appropriate, procedures to facilitate the implementation of the Call Detail Record (CDR) policy and associated audit controls.

From Voice Video Policy Security Technical Implementation Guide

Part of SRG-POL-300138

Associated with: CCI-001834

VVSP-01-000027_rule The organization must disseminate to the ISSO and ISSM and others, as the local organization deems appropriate, procedures to facilitate the implementation of the Call Detail Record (CDR) policy and associated audit controls.

Vulnerability discussion

The audit and accountability procedures implement audit and accountability policy. Organizational procedures must reflect applicable NIST and STIG guidance by determining applicable STIGs and SRGs and identifying the applicable audit and accountability controls and procedures. Disseminating the implementation procedures for the CDR policy and associated controls addressing session initiation, status, and participants, using common date and time elements, to the ISSO and ISSM, and others as the local organization deems appropriate, reduces the likelihood of individuals putting the Voice Video system at risk, either deliberately or inadvertently. Dissemination techniques may include sending the implementation procedures of the CDR policy via email, posting on wiki or in SharePoint repositories, STIG, configuration guides, and other forms of communication.

Check content

Review the procedures to facilitate CDR policy and associated access controls via the organizations information sharing capability to ensure the organization disseminates the implementation procedures to the ISSO and ISSM and others the local organization deems appropriate. Methods for disseminating the implementation procedures include sending these via email, posting on wiki or in SharePoint repositories, and other forms of documented communication. If the procedures to facilitate CDR policy and associated controls is not disseminated via the organizations information sharing capability to the ISSO and ISSM and others the local organization deems appropriate, this is a finding.

Fix text

Disseminate the procedures to facilitate the implementation of CDR policy and associated access controls to the ISSO and ISSM and others the local organization deems appropriate. Methods for disseminating the Voice Video access control policy include sending the policy via email, posting on wiki or in SharePoint repositories, and other forms of documented communication.

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer