19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Safeguard Catalogue - Communications Remarks<br />

____________________________________________________________________ .........................................<br />

To ensure the fault-free operation of the fax server, it is also necessary to<br />

specify who is responsible for administration of the hardware components, the<br />

operating system and the fax server application. A fax mail centre should be<br />

set up (see also S 2.180 Setting up a fax mail centre). <strong>The</strong> administration<br />

personnel and the staff employed in the fax mail centre must be given training<br />

on the operating system and fax server application. To avoid disruption due to<br />

improper use, the users must also be trained in operation of the fax client<br />

application.<br />

Often the permissions which can be granted to users and user groups on fax<br />

servers for incoming fax transmissions include:<br />

- Read rights,<br />

- Forwarding rights<br />

- Delete rights.<br />

For outgoing fax transmissions, often the following rights can be granted:<br />

- Send rights,<br />

- Suspend rights,<br />

- Delete rights,<br />

- right to modify transmission options<br />

Permissions should be granted in accordance with the provisions contained in<br />

the fax security guidelines (see also S 2.178 Creation of security guidelines<br />

for the use of the fax server).<br />

Unless it is possible to ensure by technical means that fax transmissions are<br />

forwarded immediately, access rights should be granted in such a manner that<br />

only authorised users can access the relevant "mailboxes" on the server.<br />

As a general rule, access to temporary areas in which the fax server<br />

application stores fax transmissions temporarily prior to their being sent out or<br />

distributed to recipients should only be granted to privileged users (e.g.<br />

administrators, fax mail centre).<br />

<strong>The</strong> connections of the fax server to the private branch exchange or to the<br />

public switched telephone network should be checked at regular intervals to<br />

ensure that they are working properly. Where the fax server is linked to<br />

internal communications systems, such as, for example, an e-mail system or a<br />

workflow management system, the functioning of these connections should<br />

similarly be checked at regular intervals.<br />

Regular checks must also be performed to ensure that sufficient hard disk<br />

space is available for storage of fax transmissions (see also S 5.75 Protecting<br />

against overloading the fax server). If the hard disk space becomes exhausted,<br />

no further fax transmissions can be received or sent.<br />

<strong>The</strong> fax server activities must be logged in accordance with the provisions of<br />

the fax security guidelines and the logs must be examined at regular intervals<br />

(see also S 2.64 Checking the log files and S 5.25 Using transmission and<br />

reception logs). When specifying the extent and content of logs, the need for<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000<br />

Responsibility for<br />

administration<br />

Granting of permissions<br />

on fax servers<br />

Granting of access<br />

rights<br />

Checking of available<br />

hard disk space<br />

Analysis of log data

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!