19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Safeguard Catalogue - Personnel Remarks<br />

____________________________________________________________________ .........................................<br />

S 3.13 Increasing staff awareness of potential threats<br />

to the PBX<br />

Initiation responsibility: PBX officer; <strong>IT</strong> Security Management;<br />

personnel committee/works council<br />

Implementation responsibility: <strong>IT</strong> Security Management, Administrators<br />

Staff members must be advised of the risks involved in the use of a digital<br />

PBX (telecommunications facility). This could be done, for instance, by<br />

means of a short briefing or instruction sheets. It must be borne in mind that<br />

abnormal behaviour of a PBX should be reported. Since in case of<br />

manipulations of a PBX installation, involvement of the PBX operator cannot<br />

be precluded, an independent controller, such as <strong>IT</strong> Security Management or<br />

departmental data security officers, should be informed in such cases.<br />

Additional controls:<br />

- Is awareness training repeated in regular intervals?<br />

- Are new employees made aware of the possible dangers involved in PBX<br />

operation?<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!