From Voice Video Policy Security Technical Implementation Guide
Part of SRG-POL-300611
Associated with: CCI-003072
The information security architecture at the individual information system level must be consistent with and complement the more global, organization-wide information security architecture that is integral to and developed as part of the enterprise architecture. The information security architecture includes an architectural description, the placement/allocation of security functionality (including security controls), security-related information for external interfaces, information being exchanged across the interfaces, and the protection mechanisms associated with each interface.
Review each organizational Voice Video SSP. Confirm the Voice Video system uses session media encryption to provide end-to-end interoperable confidentiality and integrity. The Voice Video components within the VoIP system that must be protected are endpoints, media gateways, session mangers (gatekeepers, session controllers, soft switches, etc.), border elements (session border controllers, routers, firewalls, etc.), and other network devices involved in the session media. Session media encryption meeting UCR requirements must be implemented end to end. If the SSP for the Voice Video system does not document the Voice Video session media encryption used to provide end-to-end interoperable confidentiality and integrity, this is a finding.
Implement and document in the Voice Video SSP the session media encryption used to provide end-to-end interoperable confidentiality and integrity. Configure the Voice Video system components per the DoDIN APL deployment guide specific to the product being deployed.
Lavender hyperlinks in small type off to the right (of CSS
class id
, if you view the page source) point to
globally unique URIs for each document and item. Copy the
link location and paste anywhere you need to talk
unambiguously about these things.
You can obtain data about documents and items in other
formats. Simply provide an HTTP header Accept:
text/turtle
or
Accept: application/rdf+xml
.
Powered by sagemincer