19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Safeguard Catalogue - Hardware & Software Remarks<br />

____________________________________________________________________ .........................................<br />

S 4.6 Audit of the PBX configuration<br />

(target/performance reconciliation)<br />

Initiation responsibility: PBX officer; <strong>IT</strong> Security Management<br />

Implementation responsibility: <strong>IT</strong> security management, revisor<br />

After each configuration change, e.g. release of a subscriber's authorisation,<br />

this should be recorded in an ACTUAL inventory. That list may be kept<br />

manually or by automatic means. Periodically (not necessarily at regular<br />

intervals), e.g. every six months, reconciliation checks should, at least<br />

randomly, be made of such an ACTUAL inventory and of the actual status.<br />

Incongruities should be cleared by means of the listings/audit trails. In particular,<br />

it should be verified whether<br />

- all dialling numbers not allocated have actually not been set up;<br />

- unpermitted authorisations have indeed not been granted to anybody;<br />

- de-activated user facilities are assuredly inactive.<br />

- de-activated dial-in functions are assuredly inactive.<br />

In collaboration with ZVEI, the Central Association of the Electrical and<br />

Electronics Industry, BSI has drawn up a catalogue of requirements which<br />

contains improved audit. This catalogue is to be used when purchasing new<br />

PBX systems for federal agencies. In the event that PBX systems are already<br />

in place, the extent to which manufacturers can offer improvements as updates<br />

should be reviewed.<br />

Additional controls:<br />

- Is it possible, by reference to the available documents, to provide<br />

information, e.g. on the rights of particular subscriber's stations/lines?<br />

- When was the documentation last reviewed for congruity with the actual<br />

state of affairs?<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!