The organization must implement and document the Media Gateway (MG) and any Signaling Gateway (SG) used to connect unclassified Voice Video systems to DISA SBU Voice.

From Voice Video Policy Security Technical Implementation Guide

Part of SRG-POL-400019

Associated with: CCI-002073

VVSP-01-000044_rule The organization must implement and document the Media Gateway (MG) and any Signaling Gateway (SG) used to connect unclassified Voice Video systems to DISA SBU Voice.

Vulnerability discussion

Organizations must carefully consider the risks that may be introduced when information systems (i.e., system interconnections) are connected to other systems with different security requirements and security controls, both within organizations and external to organizations. Authorizing Officials must determine the risk associated with information system connections and the appropriate controls employed. Risk considerations also include information systems sharing the same networks. Organizations typically do not have control over external networks (e.g., the Internet). Approved boundary protection devices (e.g., routers, firewalls, border controllers) mediate communications (i.e., information flows) between unclassified national security systems and external networks. Boundary protection is required for processing, storing, or transmitting all Voice Video media and signaling. For Voice Video, connection of unclassified systems to external systems requires an MG and SG when circuit-switched and IP networks are interconnected supporting Command and Control (C2) users.

Check content

If the Voice Video system only uses individual PSTN subscriber lines terminated on individual phones, a dedicated key system, or a dedicated PBX, which is isolated from all DoD networks, this is not applicable. This configuration will not support DISN Voice Precedence user requirements. Review each Voice Video system security plan (SSP). Confirm the organization implements and documents the MG and any SG used to connect an unclassified Voice Video system to DISA SBU Voice. Interconnected networks supporting mission-critical decision-making users must provide for DISN Voice Precedence and Assured Service to be conducted across the gateway. Verify that local DISA SBU Voice access for intra-DoD dialup services to/from a Voice Video system within a site enclave and a DSN number is via a local MG to a circuit-switched DSA SBU Voice service. Enclaves supporting DISN Voice Precedence must use one or more T619A trunks providing multilevel precedence and preemption (MLPP) functionality. Enclaves not supporting DISN Voice Precedence may use PRI or CAS trunks. The following exceptions apply: - The VoIP system within the enclave is approved for DISA SBU Voice IP service. - The VoIP system within a site enclave is subtended to a larger enclave. - The enclave is part of an organizational intranet connected using dedicated circuits or VPN tunnels, whether site-to-site or meshed. If each Voice Video SSP does not implement and document the MG and any SG used to connect an unclassified Voice Video system to DISA SBU Voice, this is a finding. If the documented MG and any SG do not provide DISN Voice Precedence and Assured Service to support mission-critical decision-making users, this is a finding. Note: Trunks that support SS7 signaling and SS7-based signaling between a DoD network and a non-DOD network are prohibited.

Fix text

Implement and document the MG and any SG used to connect an unclassified Voice Video system to DISA SBU Voice. Interconnected networks supporting mission-critical decision-making users must provide for DISN Voice Precedence and Assured Service to be conducted across the gateway. Local DISA SBU Voice access for intra-DoD dialup services to/from a Voice Video system within a site enclave and a DSN number must be through a local MG to a circuit-switched DSA SBU Voice service. Enclaves supporting DISN Voice Precedence must use one or more T619A trunks providing multilevel precedence and preemption (MLPP) functionality. Enclaves not supporting DISN Voice Precedence may use PRI or CAS trunks. Note: Trunks that support SS7 signaling and SS7-based signaling between a DoD network and a non-DOD network are prohibited.

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer