19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Safeguard Catalogue - Communications Remarks<br />

____________________________________________________________________ .........................................<br />

S 5.25 Using transmission and reception logs<br />

Initiation responsibility: <strong>IT</strong> Security Management<br />

Implementation responsibility: <strong>IT</strong> Security Management, Fax Officer, Fax<br />

Office<br />

When fax services are used, a distinction must be made as regards the use of<br />

transmission and reception logs between conventional fax machines and fax<br />

servers.<br />

Use of a conventional fax machine<br />

Lists of completed transmissions (journals) which are compiled automatically<br />

by the fax machine must be printed out regularly. Who is responsible for these<br />

printouts, how long they are kept for, and in what form sample checks for<br />

irregularities are made on them must all be specified. <strong>The</strong> requirements of the<br />

Federal Data Privacy <strong>Protection</strong> Act must be observed here. In particular,<br />

access by unauthorised persons must be prevented.<br />

A fax journal listing the senders and recipients of fax messages should also be<br />

kept. Optionally, a log of incoming faxes can be kept as well.<br />

Another means of checking is available where the fax machine is connected to<br />

a modern private branch exchange, in which case it is possible, for example, to<br />

evaluate the call charge data records for the fax subscriber number in the PBX<br />

(cf. S 2.40 Timely involvement of the staff council / works council).<br />

Use of a fax server<br />

It is also possible to log transmissions on fax servers. <strong>The</strong>se logs should be<br />

evaluated and archived regularly. It is especially necessary to define the basic<br />

requirements and responsibilities for processing, interpreting and archiving of<br />

the logs.<br />

Thus, for example, one option is that the fax mail centre is responsible for<br />

these activities but that the logs can only be evaluated in the presence of a<br />

member of the works council or staff council or a member of the audit or data<br />

privacy team. Once again, the requirements of the Federal Data Privacy<br />

<strong>Protection</strong> Act must be observed and access by unauthorised parties must be<br />

prevented.<br />

When fax servers are used, it is inappropriate to keep manual fax journals.<br />

Instead, it should be sufficient to archive the transmission and reception logs<br />

in their entirety.<br />

It may sometimes also be possible to use the data records of charges incurred<br />

for outgoing fax transmissions from the fax server to pass on these costs based<br />

on usage.<br />

Additional controls:<br />

- What procedures apply to the checking of transmission and reception logs?<br />

- Where are the logs archived and who can access them?<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000<br />

Check transmission and<br />

reception logs regularly<br />

Maintaining a fax journal<br />

Evaluate log files<br />

regularly

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!