Security News > 2021 > June > NSA Releases Guidance for Securing Enterprise Communication Systems

NSA Releases Guidance for Securing Enterprise Communication Systems
2021-06-18 12:32

The NSA on Thursday released guidance to help organizations secure their communication systems, specifically Unified Communications and Voice and Video over IP. UC and VVoIP are call-processing systems that are used for communications and collaboration by many enterprises, including government agencies and their contractors.

The NSA has warned that if these systems are not properly secured, they are exposed to the same risks as IP systems, including software vulnerabilities and various types of malware.

In an effort to help organizations secure UC and VVoIP systems, the NSA has released a 43-page guide that describes network, perimeter, enterprise session controller, and endpoint security best practices and mitigations.

The NSA's recommendations include using VLANs to separate UC/VVoIP systems from the data network, implementing layer 2 protections, ensuring that all UC/VVoIP connections are authenticated, ensuring that systems are patched, authenticating and encrypting signaling and media traffic, using fraud detection solutions, implementing mechanisms for preventing DoS attacks, ensuring that systems are physically secure, and performing tests before adding new devices to operational networks.

"Taking advantage of the benefits of a UC/VVoIP system, such as cost savings in operations or advanced call processing, comes with the potential for additional risk," the NSA said.

The NSA has released many guides and advisories over the past year in an effort to help public and private sector organizations protect their systems against cyber threats.


News URL

http://feedproxy.google.com/~r/securityweek/~3/LXXNEi89NLw/nsa-releases-guidance-securing-enterprise-communication-systems

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
NSA 2 0 12 0 2 14