The organization must train users of unclassified Voice Video endpoints having a camera or video capability to prevent the pickup and transmission of sensitive or classified information.

From Voice Video Policy Security Technical Implementation Guide

Part of SRG-POL-300605

Associated with: CCI-001639

VVSP-01-000126_rule The organization must train users of unclassified Voice Video endpoints having a camera or video capability to prevent the pickup and transmission of sensitive or classified information.

Vulnerability discussion

Organizations consider rules of behavior based on individual user roles and responsibilities. Rules of behavior for both organizational and non-organizational users are essential for general unclassified communications and other specific or classified communications, which may require restrictions for those who may participate. The signed acknowledgment (user agreement) may be satisfied by the security awareness training and role-based security training programs conducted by organizations if such training includes rules of behavior.For Voice Video systems, the unclassified phone system typically also performs as an emergency contact system. Callers may need to report conditions for fire and emergency services (FES). Additionally, mission-critical decision-making users may need to initiate or receive high-priority calls for dissemination of crisis information using the DISN Voice Precedence services. Users must be trained to know and practice correct handling of these calls and must sign agreements prior to use. Other Voice Video systems, such as video conferencing and classified systems, may warrant additional user training and agreements.Voice Video endpoints have camera and video capabilities that require special training, especially in areas where classified information may be present or discussed. Users must not inadvertently display information of a sensitive or classified nature that is not part of the communications session while the camera is active. There is a risk when information in the form of charts, pictures, or maps is displayed within range of a camera. Any pan, tilt, and zoom (PTZ) capabilities of the camera and video enhancement must be considered.

Check content

Review the organizational Voice Video training plan. Verify the plan includes user training regarding Voice Video endpoints with camera or video capability to potentially pick up and transmit sensitive or classified information. Prior to operating unclassified Voice Video endpoints with camera or video capability, users must be trained specifically on the following: - Conference room and office users do not display sensitive or classified information on walls within view of cameras. - Conference room and office users do not place sensitive or classified information on tables or desks within view of cameras without proper protection (e.g., proper cover). - Conference room and office users do not read or view sensitive or classified information at such an angle that cameras could focus on it. - Potential for cameras to be activated inadvertently and relevant mitigations. - PTZ capabilities of the camera and video enhancement. If the organizational Voice Video training plan does not include user training regarding Voice Video endpoints with camera or video capability to potentially pick up and transmit sensitive or classified information, this is a finding. NOTE: This requirement is relevant for all session classification levels. The session classification is dependent on the classification of the network and facility. Classified communications may occur at the same level as the network and facility, but communications at a lower classification or no classification (e.g., Unclassified or For Official Use Only [FOUO]) may also occur in the same environment.

Fix text

Document in the organizational Voice Video training plan training material includes Voice Video endpoints with camera or video capability to potentially pick up and transmit sensitive or classified information. Ensure that, prior to operating unclassified Voice Video endpoints with camera or video capability, users are trained specifically on the following: - Conference room and office users do not display sensitive or classified information on walls within view of cameras. - Conference room and office users do not place sensitive or classified information on tables or desks within view of cameras without proper protection (e.g., proper cover). - Conference room and office users do not read or view sensitive or classified information at such an angle that cameras could focus on it. - Potential for cameras to be activated inadvertently and related mitigations. - PTZ capabilities of the camera and video enhancement.

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer