The Enterprise Voice, Video, and Messaging Session Manager must be configured to generate session (call) records that provide information necessary for corrective actions without revealing personally identifiable information or sensitive information.
Overview
| Finding ID | Version | Rule ID | IA Controls | Severity |
| V-260019 | SRG-NET-000273-VVSM-00101 | SV-260019r949018_rule | CCI-001312 | medium |
| Description | ||||
| Any Enterprise Voice, Video, and Messaging Session Manager providing too much information in session records risks compromising the data and security of the application and system. The structure and content of session records must be carefully considered by the organization and development team. | ||||
| STIG | Date | |||
| Enterprise Voice, Video, and Messaging Session Management Security Requirements Guide | 2024-03-11 | |||
Details
Check Text (C-260019r949018_chk)
Verify the Enterprise Voice, Video, and Messaging Session Manager generates session records that provide information necessary for corrective actions without revealing personally identifiable information or sensitive information.
If the Enterprise Voice, Video, and Messaging Session Manager does not generate session records that provide information necessary for corrective actions without revealing personally identifiable information or sensitive information, this is a finding.
Fix Text (F-63657r949017_fix)
Configure the Enterprise Voice, Video, and Messaging Session Manager to generate session records that provide information necessary for corrective actions without revealing personally identifiable information or sensitive information.