Skip to content
ControlVerdict
SC.L2-3.13.14addresses
SC.L2-3.13.14Voice Over Internet Protocol
Control and monitor the use of Voice over Internet Protocol (VoIP) technologies.
  • [a]

    use of Voice over Internet Protocol (VoIP) technologies is controlled; and
  • [b]

    use of Voice over Internet Protocol (VoIP) technologies is monitored.

View full control

One sanctioned VoIP platform on a voice VLAN, with call records and toll-fraud alerting reviewed

ControlVerdict Corpus@cv-corpusOSCJul 31, 2026
Community is just starting — add yours. No verdicts yet.

Implementation

AO coverage. Addresses both Voice Over Internet Protocol objectives: use of VoIP is controlled, and use of VoIP is monitored.

Sanctioned platform. One cloud PBX is approved for business voice. Consumer voice and messaging apps are not blocked outright on personal phones, but policy prohibits discussing CUI on them and they are not permitted on managed endpoints that hold CUI. Naming a single platform is the control that makes the rest of this testable.

Control [a]. Desk phones sit on a dedicated voice VLAN whose firewall policy permits only the provider's signaling and media ranges plus provisioning and NTP; the voice VLAN has no route to the enclave. Phones authenticate to the PBX with per-device credentials rather than a shared secret, and provisioning is over TLS with configuration files that do not contain reusable secrets. Signaling uses TLS and media uses SRTP where the carrier supports it. Softphone use is limited to managed endpoints through the same identity and device-compliance path as other applications. Administrative access to the PBX console is restricted to privileged accounts from the management path, and international and premium-rate dialing is disabled by default with per-user enablement by ticket.

Monitoring [b]. Call detail records are retained per the retention standard and reviewed for anomalies: calls to high-risk destinations, after-hours volume spikes, and unusual call duration patterns that suggest toll fraud or a compromised extension. The session border controller alerts on registration attempts from unexpected addresses and on rate anomalies. PBX administrative changes — new extension, forwarding rule, trunk change — log to the SIEM, because call forwarding to an external number is the quiet way voice gets redirected. Voicemail-to-email delivery is monitored for forwarding rules to external addresses.

Maintenance. Monthly CDR anomaly review with a named reviewer. Quarterly reconciliation of active extensions against the employee roster, since orphaned extensions are the usual toll-fraud entry point. Firmware for phones and the SBC is patched under the flaw remediation SLA.

Accepted gap. Two shop-floor analog phones behind an ATA cannot support TLS or SRTP. They are on the voice VLAN with no enclave route, are used for internal paging and facilities calls only, and are documented as not for CUI discussion.

What the evidence looks like

  • PBX configuration showing per-device authentication, TLS signaling, and disabled international dialing by default
  • Voice VLAN firewall rules limited to the provider ranges with no enclave route
  • Monthly call detail record anomaly review notes with reviewer and date
  • SIEM detections for PBX administrative changes and forwarding-rule creation
  • Quarterly extension-to-roster reconciliation and the analog phone exception

Environment

Cloud PBX serving desk phones and softphones, a SIP trunk to the carrier, and a policy that CUI is not discussed on unmanaged consumer voice apps.

Tools

Was this example useful?

Quick reaction — no account needed. For reasoning that moves the community meter, cast a full verdict below.

Discussion(0)

No discussion on this example yet

Verdicts capture a conclusion. Use a thread when the interesting part is the argument.

Sign in to start a thread.