- Treat VoIP infrastructure as in-scope systems: segment voice traffic, restrict management interfaces, and keep call-processing servers patched.
- Cloud telephony shifts the question without removing it — the tenant configuration and its integration points are what remain to watch.
3.13.14 — VoIP control
3.13 System and Communications Protection · NIST SP 800-171 Rev. 2 · The heading label is this site's navigational shorthand; the official language is the statement below.
Control and monitor the use of Voice over Internet Protocol (VoIP) technologies.
NIST SP 800-171 Rev. 2 — Protecting CUI in Nonfederal Systems ↗NIST SP 800-171A — Assessing Security Requirements for CUI ↗What this requirement is after
Rev. 2 calls out Voice over IP specifically: when calls travel the data network, the calling infrastructure runs under the same discipline — approved usage, monitored operation — as any other networked service, because a VoIP system is a networked application with an attractive attack surface.
Rev. 3 retires this technology-specific requirement — the 03.13.14 slot is withdrawn with no direct successor. Its substance is generally covered by boundary, transmission-protection, and monitoring expectations, but verify the official disposition against NIST's analysis of changes before dropping anything from documentation.
Brilliant at the Basics practices that support this requirement
The campaign’s twenty practices are a priority list, not a control catalog, and none of them works this requirement’s substance directly. It still applies to you if it is in your contract’s scope: address it through your own implementation and the related artifacts below, and treat the absence of a mapping here as honesty, not permission to skip it.
Implementation considerations and evidence
- Segmentation and management-access configuration for voice systems
- Monitoring or log records covering the VoIP platform
Templates and worksheets with a mapped relationship
No artifact in the library names this requirement yet. The library index groups everything by category and practice.
Where this lands in Rev. 3
No direct Rev. 3 counterpart — see the transition crosswalk for where this requirement's substance went. Open the transition crosswalk →
Sources and review status
| Primary sources | NIST SP 800-171 Rev. 2 — Protecting CUI in Nonfederal Systems · NIST SP 800-171A — Assessing Security Requirements for CUI |
|---|---|
| Review status | Pending NIST SME review |
| Content version | 1.0 |
| Updated |