19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Safeguard Catalogue - Communications Remarks<br />

____________________________________________________________________ .........................................<br />

S 5.49 Callback based on CLIP/COLP<br />

Initiation responsibility: <strong>IT</strong> Security Management, Administrators<br />

Implementation responsibility: Administrators<br />

Many communication cards offer an automatic callback function. If this<br />

function is active and the communication card receives a call, it waits for a<br />

connection to be established successfully, then closes it down again<br />

immediately, and calls a preset number back. This prevents unauthorised<br />

callers from misusing a remote port as long as access is not possible via a<br />

preset number. Callback should be used whenever a specific communications<br />

partner needs to dial in automatically. It should be noted that automatic<br />

callback also accepts the costs of data transfer.<br />

ISDN offers a variant of callback to a specific subscriber number: Using<br />

Calling Line Identification Presentation (CLIP), the addressed ISDN card<br />

identifies the source of the call request and compares the forwarded subscriber<br />

number with a table of subscriber numbers. If a valid subscriber number was<br />

forwarded via CLIP, the corresponding number stored in the table is called<br />

back.<br />

An advantage here, compared with authentication exclusively via CLIP/COLP<br />

(refer to S 5.48 Authentication via CLIP/COLP), is that even if an<br />

unauthorised subscriber feigns an authorised call number, the call request is<br />

refused because the unauthorised subscriber cannot be accessed via the<br />

specified callback number.<br />

Additional controls:<br />

- Has payment of costs in the callback mode been clarified?<br />

- When were preset call numbers last checked?<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!