19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Safeguard Catalogue - Hardware & Software Remarks<br />

____________________________________________________________________ .........................................<br />

S 4.8 <strong>Protection</strong> of the PBX operator's console<br />

Initiation responsibility: PBX officer; <strong>IT</strong> Security Management<br />

Implementation responsibility: Administrators<br />

Where administration of a PBX is ensured by means of an operator's PC, the<br />

latter must be provided, as a minimum, with the safeguards usually furnished<br />

for PCs (cf. Part I, Chapter 5.1 DOS PC (single user)).<br />

Optionally:<br />

In the event that the PBX system does not have sufficient security functions<br />

for the management of rights and access protection, the use of conventional<br />

devices (port controllers) available on the market may be considered. Using<br />

devices of this kind, reliable identification and authentication procedures can<br />

be carried out.<br />

Additional controls:<br />

- Has the operator's PC been provided with password protection?<br />

- Is the operator's PC installed in a secure environment?<br />

- Who can access the operator's PC?<br />

- Who has access rights to the operator's PC?<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!