The organization must obtain alternate telecommunications services from providers that are separated from primary service providers to reduce susceptibility to the same threats.

From Voice Video Policy Security Technical Implementation Guide

Part of SRG-POL-300417

Associated with: CCI-000531

VVSP-01-000084_rule The organization must obtain alternate telecommunications services from providers that are separated from primary service providers to reduce susceptibility to the same threats.

Vulnerability discussion

This control applies to telecommunications services (data and voice) for primary and alternate processing and storage sites. Alternate telecommunications services reflect the continuity requirements in contingency plans to maintain essential missions/business functions despite the loss of primary telecommunications services. Organizations may specify different time periods for primary/alternate sites. Alternate telecommunications services include, for example, additional organizational or commercial ground-based circuits/lines or satellites in lieu of ground-based communications. Organizations consider factors such as availability, quality of service, and access when entering into alternate telecommunications agreements.Threats that affect telecommunications services are typically defined in organizational assessments of risk and include, for example, natural disasters, structural failures, hostile cyber/physical attacks, and errors of omission/commission. Organizations seek to reduce common susceptibilities by, for example, minimizing shared infrastructure among telecommunications service providers and achieving sufficient geographic separation between services. Organizations may consider using a single service provider in situations where the service provider can provide alternate telecommunications services meeting the separation needs addressed in the risk assessment. For Voice Video systems, contingency planning must also consider fire and emergency services (FES) requirements for life safety and Command and Control (C2) requirements mandating communications among top-level officials, especially during crisis conditions.

Check content

Review the contingency plan for the Voice Video system that addresses essential missions and business functions. Ensure the organization obtains alternate telecommunications services from providers that are separated from primary service providers to reduce susceptibility to the same threats. If the organization does not obtain alternate telecommunications services from providers that are separated from primary service providers to reduce susceptibility to the same threats, this is a finding.

Fix text

Develop and document a contingency plan for the Voice Video system. As part of this plan, obtain alternate telecommunications services from providers that are separated from primary service providers to reduce susceptibility to the same threats.

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer