DKDavid Koran& Associates
Home The CMMC Guide Part III · System and Communications Protection SC.L2-3.13.14
The CMMC Guide · System and Communications Protection Family

SC.L2-3.13.14  Control and Monitor VoIP

Control and monitor the use of Voice over Internet Protocol (VoIP) technologies.

Family
System and Communications ProtectionSC, 16 requirements
Point Value
1Lower weight, but not POA&M exempt
POA&M Eligible
YesOne-point requirement, may be deferred
Objectives
TwoPer NIST SP 800-171A

1Overview

SC.L2-3.13.14 applies the same control-and-monitor discipline to Voice over Internet Protocol. It requires that the use of VoIP technologies be controlled and monitored, so that internet-based voice communication is governed and observed rather than deployed as an unmanaged network service. It is a one-point requirement and may be deferred on a plan of action.

VoIP carries voice over the data network, which means it shares the network's exposures and adds its own: it can be a path for eavesdropping, toll fraud, or a foothold if left unmanaged. This control requires that its use be controlled, governed by how VoIP is configured and permitted, and monitored, so that its use is observed. The two assessment objectives are controlling and monitoring the use of VoIP.

The requirement · NIST SP 800-171 Rev 2, 3.13.14

Control and monitor the use of Voice over Internet Protocol (VoIP) technologies.

The requirement pairs control and monitoring for VoIP. Controlling its use means governing how VoIP is deployed and configured, restricting it to intended uses and securing it against misuse. Monitoring its use means observing VoIP activity so that anomalies or abuse can be detected. Together they treat VoIP as a managed service on the network rather than an unmanaged one.

2The Assessment Objectives

NIST SP 800-171A decomposes 3.13.14 into two objectives: control and monitor the use of VoIP.

[a]

The use of VoIP technologies is controlled. How VoIP is deployed and used is governed.

MeetsThe use of VoIP is controlled through configuration and policy.
FailsVoIP is deployed without control.
[b]

The use of VoIP technologies is monitored. VoIP activity is observed.

MeetsThe use of VoIP is monitored.
FailsVoIP activity is unmonitored.

The two objectives are control and monitoring. The common gap is at objective [b], where VoIP is configured but its use is not actually monitored. The assessor looks for both control and monitoring of VoIP where it is in use.

3Failure Patterns

The failures are about VoIP deployed as an unmanaged service.

Unmanaged VoIP

VoIP deployed without control can be a path for eavesdropping or fraud. Controlling its use governs how it is configured and permitted.

Control without monitoring

Configuring VoIP securely without monitoring its use misses abuse and anomalies. Monitoring completes the control.

VoIP outside the security scope

Treating VoIP as a phone system rather than a network service leaves it outside network security. It has to be controlled and monitored like other network technologies.

The common root
This control fails when VoIP is seen as telephony rather than as a network application. It runs on the data network and carries the network's risks plus its own, so leaving it unmanaged treats a network service as if it were outside security. Controlling and monitoring its use brings it into the same governance as the rest of the network.

4Ownership

This is an IT and network-owned control.

RoleResponsibility for this control
IT and networkControls and monitors VoIP deployment and use. Owns the VoIP configuration and monitoring evidence.
Security or compliance leadConfirms VoIP use is both controlled and monitored.
Program leadDocuments the VoIP controls.
See also: This control parallels the mobile-code governance of SC.L2-3.13.13 and works with the boundary protection of SC.L2-3.13.1.

5Tooling

The control is delivered by VoIP configuration and monitoring.

ObjectiveToolingWhat it provides
[a]VoIP configuration and policyControlled use of VoIP.
[b]VoIP and network monitoringMonitored use of VoIP.

The caveat is that both control and monitoring have to be present where VoIP is used. Secure configuration without monitoring, or VoIP left outside the security scope, leaves the control unmet. The assessor examines control and monitoring, so both objectives have to hold.

6Evidence

The satisfied version of 3.13.14 shows VoIP controlled and monitored.

EvidenceWhat it demonstrates
VoIP configurationObjective [a]. Use controlled.
Monitoring recordsObjective [b]. Use monitored.

The evidence should show the use of VoIP controlled through configuration and monitored. The VoIP configuration together with the monitoring records is the clearest demonstration of the control.

VoIP is a network service, not just a phone

VoIP runs on the data network and carries its risks, so this control asks that its use be controlled and monitored like any network technology. Governing and observing VoIP is part of the onsite readiness work this practice does.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.13.14. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.13.14[a] and 3.13.14[b]. csrc.nist.gov
  3. 32 CFR 170.21, Plan of Action and Milestones Requirements, governing which requirements may remain open at a Level 2 assessment. ecfr.gov
← Previous in System and Communications Protection
SC.L2-3.13.13 · Control and Monitor Mobile Code
Next in System and Communications Protection →
SC.L2-3.13.15 · Protect Communications Session Authenticity
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry SC.L2-3.13.14 · Edition 2026.1 · Last reviewed July 12, 2026