The organization must implement and document the Media Gateway (MG) and any Signaling Gateway (SG) used to connect all unclassified Voice Video systems to an external network.

From Voice Video Policy Security Technical Implementation Guide

Part of SRG-POL-400019

Associated with: CCI-002073

VVSP-01-000043_rule The organization must implement and document the Media Gateway (MG) and any Signaling Gateway (SG) used to connect all unclassified Voice Video systems to an external network.

Vulnerability discussion

Organizations must carefully consider the risks that may be introduced when information systems (i.e., system interconnections) are connected to other systems with different security requirements and security controls, both within organizations and external to organizations. Authorizing Officials determine the risk associated with information system connections and the appropriate controls employed. Risk considerations also include information systems sharing the same networks. Organizations typically do not have control over external networks (e.g., the Internet). Approved boundary protection devices (e.g., routers, firewalls, border controllers) mediate communications (i.e., information flows) between unclassified national security systems and external networks. Boundary protection is required for processing, storing, or transmitting all Voice Video media and signaling. For Voice Video, connection of unclassified systems to external systems requires an MG and SG when circuit-switched and IP networks are interconnected supporting Command and Control (C2) users.

Check content

If the Voice Video system only uses individual PSTN subscriber lines terminated on individual phones, a dedicated key system, or a dedicated PBX, which is isolated from all DoD networks, this is not applicable. This configuration will not support DISN Voice Precedence user requirements. Review each Voice Video system security plan (SSP). Confirm the organization implements and documents the MG and any SG used to connect circuit-switched and IP networks. All connections from a local site to an external network, including all commercial services, must be through documented and approved gateways. If each Voice Video SSP does not implement and document the MG and any SG used to connect circuit-switched and IP networks, this is a finding.

Fix text

Implement and document the MG and any SG used to connect all unclassified Voice Video systems to an external network. All Voice Video system access to/from the service provider must connect through an MG using a PRI or CAS trunk to the PSTN.

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer