From Voice Video Policy Security Technical Implementation Guide
Part of SRG-POL-300154
Associated with: CCI-000148
Audit review, analysis, and reporting covers information security-related auditing performed by organizations including, for example, auditing that results from monitoring of account usage, remote access, wireless connectivity, mobile device connection, configuration settings, system component inventory, use of maintenance tools and nonlocal maintenance, physical access, temperature and humidity, equipment delivery and removal, communications at the information system boundaries, use of mobile code, and use of VoIP.
Review the CDR policy and supporting documentation to confirm the organization reviews and analyzes Voice Video system CDRs at least every seven days for indications of inappropriate or unusual activity. If the organization does not review and analyze all Voice Video system CDRs at least every seven days for indications of inappropriate or unusual activity, this is a finding.
Document in the CDR policy or supporting documentation the reviews and analysis of Voice Video system CDRs at least every seven days for indications of inappropriate or unusual activity. Maintain an audit trail of review and update activity.
	Lavender hyperlinks in small type off to the right (of CSS
	class id, if you view the page source) point to
	globally unique URIs for each document and item. Copy the
	link location and paste anywhere you need to talk
	unambiguously about these things.
	
      
	You can obtain data about documents and items in other
	formats. Simply provide an HTTP header Accept:
	text/turtle or
	Accept: application/rdf+xml.
      
Powered by sagemincer