19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Safeguard Catalogue - Communications Remarks<br />

____________________________________________________________________ .........................................<br />

S 5.55 Checking of alias files and distribution lists<br />

Initiation responsibility: Head of <strong>IT</strong> Section, <strong>IT</strong> Security Management<br />

Implementation responsibility: Administrator, <strong>IT</strong> users<br />

Alias files and distribution lists are often used to facilitate the addressing of email.<br />

If alias files are maintained on mail servers as well as mail clients,<br />

clarification is required as to which entries have priority, i.e. if an alias is<br />

duplicated on both servers, which address should be accepted on the selection<br />

of this alias. Aliases on the mail server should be decisive when e-mail is<br />

received, aliases on the mail client should be decisive when e-mail is<br />

dispatched. Users must be notified of aliases which are resolved by the mail<br />

server, so that they can take this into account when passing on e-mail<br />

addresses.<br />

Users must have read-access to alias files on the mail server to be able to<br />

make use of these files. Only the mail administrator should have write-access<br />

to the files.<br />

To prevent e-mail from being transmitted to the wrong parties as a result of<br />

incorrect, outdated or manipulated distribution lists, these lists must be<br />

checked regularly for correctness and validity.<br />

Additional controls:<br />

- At which locations have alias files and distribution lists been stored?<br />

- Who has access to alias files and distribution lists?<br />

- When were alias files, distribution lists and stored e-mail addresses last<br />

checked for validity?<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!