19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Safeguard Catalogue - Communications Remarks<br />

____________________________________________________________________ .........................................<br />

S 5.73 Secure operation of a fax server<br />

Initiation responsibility: Head of <strong>IT</strong> Section, <strong>IT</strong> Security Management<br />

Implementation responsibility: Administrator, fax mail centre<br />

Secure operation of a fax server requires that communication is secure both<br />

locally and also over the public switched network. <strong>The</strong> fax server accepts<br />

incoming fax transmissions from other fax servers or fax machines and if the<br />

automatic fax routing function has been activated, it then routes them to the<br />

connected users. Outgoing fax transmissions sent by the connected users are<br />

passed to the fax server and then sent on to recipients. <strong>The</strong> fax server must<br />

also ensure that local fax transmissions, i.e. fax transmissions from one<br />

workstation to another within the same organisation (or organisational unit)<br />

are sent on internally and not over the public network.<br />

If the fax server is to be operated securely, then, once purchased and installed,<br />

the configuration of its operating system and the fax server application must<br />

be tested thoroughly. If any error messages are generated, the configuration<br />

settings should be altered where this is possible. <strong>The</strong> test phase should be<br />

followed by a pilot run. Only once the fax server has been demonstrated to be<br />

running without errors in this phase also should it be cleared for actual<br />

operation. <strong>The</strong> configuration parameters should be documented meticulously,<br />

as should all changes to the configuration settings.<br />

Fax servers store all incoming and outgoing fax transmissions. <strong>The</strong> length of<br />

time for which these are stored depends on the facilities provided by the fax<br />

server application and the configuration. Thus, for example, it is possible that<br />

outgoing fax transmissions are only held temporarily until a given fax job has<br />

been completed and are then deleted. Again, it could be that incoming fax<br />

transmissions are only stored temporarily until they have been re-routed to<br />

recipients, following which they are deleted. However, another possibility is<br />

that all incoming and outgoing fax transmissions are held on the fax server<br />

until they are specifically deleted by the users concerned or by the fax mail<br />

centre or Administrator. On some fax servers it is also possible to have the<br />

data automatically deleted after a defined period of time. Thus, for example,<br />

all fax transmissions more than three months old are automatically deleted.<br />

Depending on the concept of use, procedures must be defined for the deletion<br />

of fax data on the fax server. At the same time, a procedure should be laid<br />

down as to where and to what extent archiving of fax data should be<br />

performed. As a general rule, fax data should not remain on the fax server any<br />

longer than is absolutely necessary.<br />

Steps must be taken to ensure that unauthorised persons cannot access fax<br />

transmissions. As a first step, the fax server must be physically protected<br />

against unauthorised access. This can only be achieved if the server is located<br />

in a secure server room or server cabinet (see Section 4.3.2 Server room and<br />

Section 4.4 Protective cabinets).<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000<br />

Test and documentation<br />

of configuration<br />

Deletion of fax data<br />

Secure siting of the fax<br />

server

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!