Inventory every PBX, gateway, trunk, handset, softphone, switch and remote-management path. Restrict administration, replace default credentials, update supported systems, segment where appropriate, protect signaling and media using provider-supported controls, monitor unusual calling and keep a tested configuration and continuity plan. Never post SIP credentials or PBX backups in a public support form.
1. Build the voice-system inventory
- PBX/EPBX model or hosted service, software version and support status
- Trunks, lines, numbers, gateways and provider escalation contacts
- Handsets, softphones, conference devices and remote users
- Voice VLAN, switches, PoE, router, firewall, DNS/NTP and internet dependencies
- Administrative accounts, provisioning methods, backups, logs and call-detail records
- Power, failover and manual continuity paths
2. Apply layered controls
- Remove or disable default, unused and former-user accounts; use unique strong credentials and MFA where supported.
- Limit administration to trusted paths and roles; do not expose a management console broadly to the internet.
- Keep PBX, gateways, handsets and provisioning services on supported releases and verified update channels.
- Use network segmentation, firewall policy and provider-supported signaling/media protection where the design permits.
- Restrict destinations, time windows, international or premium calling according to business need and monitor anomalies.
- Protect configuration backups, voicemail, call records and logs as sensitive business data.
3. Test failure and recovery
Test how reception, critical extensions and external calling behave during internet, power, provider and PBX failures. Keep a documented configuration backup and verify that it can be restored to an appropriate supported environment.
NIST's VoIP guidance is a foundational security reference but is not a current product configuration manual. Apply its architectural risk perspective together with current vendor, provider and standards documentation.
Sources and further reading
Technical statements were reviewed against these references. External pages may change after our review date.
- NIST SP 800-58: Security Considerations for Voice Over IP Systems — National Institute of Standards and Technology
- RFC 3261: SIP — Session Initiation Protocol — RFC Editor