Microsoft Skype for Business 2016 Security Technical Implementation Guide

Overview

VersionDateFinding Count (3)Downloads
12016-11-02CAT I (High): 0CAT II (Medium): 3CAT III (Low): 0
STIG Description
The Microsoft Skype for Business 2016 Security Technical Implementation Guide (STIG) is published as a tool to improve the security of Department of Defense (DoD) information systems. Comments or proposed revisions to this document should be sent via e-mail to the following address: disa.stig_spt@mail.mil.
ClassifiedPublicSensitive
I - Mission Critical ClassifiedI - Mission Critical PublicI - Mission Critical Sensitive
II - Mission Support ClassifiedII - Mission Support PublicII - Mission Support Sensitive
III - Administrative ClassifiedIII - Administrative PublicIII - Administrative Sensitive

Findings - MAC II - Mission Support Public

Finding IDSeverityTitleDescription
V-70901
LOWMEDIUMHIGH
The ability to store user passwords in Skype must be disabled.Allows Microsoft Lync to store user passwords. If you enable this policy setting, Microsoft Lync can store a password on request from the user. If you...
V-70903
LOWMEDIUMHIGH
Session Initiation Protocol (SIP) security mode must be configured.When Lync connects to the server, it supports various authentication mechanisms. This policy allows the user to specify whether Digest and Basic auth...
V-70905
LOWMEDIUMHIGH
In the event a secure Session Initiation Protocol (SIP) connection fails, the connection must be restricted from resorting to the unencrypted HTTP.Prevents from HTTP being used for SIP connection in case TLS or TCP fail....