1Overview
SC.L2-3.13.14 applies the same control-and-monitor discipline to Voice over Internet Protocol. It requires that the use of VoIP technologies be controlled and monitored, so that internet-based voice communication is governed and observed rather than deployed as an unmanaged network service. It is a one-point requirement and may be deferred on a plan of action.
VoIP carries voice over the data network, which means it shares the network's exposures and adds its own: it can be a path for eavesdropping, toll fraud, or a foothold if left unmanaged. This control requires that its use be controlled, governed by how VoIP is configured and permitted, and monitored, so that its use is observed. The two assessment objectives are controlling and monitoring the use of VoIP.
Control and monitor the use of Voice over Internet Protocol (VoIP) technologies.
The requirement pairs control and monitoring for VoIP. Controlling its use means governing how VoIP is deployed and configured, restricting it to intended uses and securing it against misuse. Monitoring its use means observing VoIP activity so that anomalies or abuse can be detected. Together they treat VoIP as a managed service on the network rather than an unmanaged one.
2The Assessment Objectives
NIST SP 800-171A decomposes 3.13.14 into two objectives: control and monitor the use of VoIP.
The use of VoIP technologies is controlled. How VoIP is deployed and used is governed.
The use of VoIP technologies is monitored. VoIP activity is observed.
The two objectives are control and monitoring. The common gap is at objective [b], where VoIP is configured but its use is not actually monitored. The assessor looks for both control and monitoring of VoIP where it is in use.
3Failure Patterns
The failures are about VoIP deployed as an unmanaged service.
Unmanaged VoIP
VoIP deployed without control can be a path for eavesdropping or fraud. Controlling its use governs how it is configured and permitted.
Control without monitoring
Configuring VoIP securely without monitoring its use misses abuse and anomalies. Monitoring completes the control.
VoIP outside the security scope
Treating VoIP as a phone system rather than a network service leaves it outside network security. It has to be controlled and monitored like other network technologies.
4Ownership
This is an IT and network-owned control.
| Role | Responsibility for this control |
|---|---|
| IT and network | Controls and monitors VoIP deployment and use. Owns the VoIP configuration and monitoring evidence. |
| Security or compliance lead | Confirms VoIP use is both controlled and monitored. |
| Program lead | Documents the VoIP controls. |
5Tooling
The control is delivered by VoIP configuration and monitoring.
| Objective | Tooling | What it provides |
|---|---|---|
| [a] | VoIP configuration and policy | Controlled use of VoIP. |
| [b] | VoIP and network monitoring | Monitored use of VoIP. |
The caveat is that both control and monitoring have to be present where VoIP is used. Secure configuration without monitoring, or VoIP left outside the security scope, leaves the control unmet. The assessor examines control and monitoring, so both objectives have to hold.
6Evidence
The satisfied version of 3.13.14 shows VoIP controlled and monitored.
| Evidence | What it demonstrates |
|---|---|
| VoIP configuration | Objective [a]. Use controlled. |
| Monitoring records | Objective [b]. Use monitored. |
The evidence should show the use of VoIP controlled through configuration and monitored. The VoIP configuration together with the monitoring records is the clearest demonstration of the control.
VoIP is a network service, not just a phone
VoIP runs on the data network and carries its risks, so this control asks that its use be controlled and monitored like any network technology. Governing and observing VoIP is part of the onsite readiness work this practice does.
Start CMMC Readiness or call 802-335-26627Sources
- NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.13.14. csrc.nist.gov
- NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.13.14[a] and 3.13.14[b]. csrc.nist.gov
- 32 CFR 170.21, Plan of Action and Milestones Requirements, governing which requirements may remain open at a Level 2 assessment. ecfr.gov