19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Safeguard Catalogue - Communications Remarks<br />

____________________________________________________________________ .........................................<br />

S 5.74 Maintenance of fax server address books and<br />

distribution lists<br />

Initiation responsibility: Head of <strong>IT</strong> Section, <strong>IT</strong> Security Management<br />

Implementation responsibility: Administrator, fax mail centre<br />

Most fax servers provide facilities for both central and also individual address<br />

books. Central address books are available to all users of a fax server and<br />

should be maintained centrally by the fax mail centre. Individual address<br />

books can be created by any user but are generally available only to the<br />

author.<br />

It is especially important that central address books are protected against<br />

unauthorised changes. To achieve this, the user access rights for the fax server<br />

application should be granted in such a way that only the fax mail centre can<br />

alter the central address books, or, if this is not possible, then the resources of<br />

the operating system should be called on so as to achieve the same result.<br />

<strong>The</strong> fax mail centre should perform regular checks to ensure that all central<br />

address books are intact and up-to-date. Most fax servers allow several<br />

recipients to be grouped together in the address books as one group. If an<br />

adversary succeeds in manipulating such groups, he or other unauthorised<br />

persons can obtain access to confidential fax transmissions. <strong>The</strong> fax mail<br />

centre should therefore also regularly review the assignment of recipients to<br />

individual groups to ensure that these are up-to-date. Where faxes are<br />

exchanged between workstations within an organisation via the fax server, the<br />

fax mail centre must keep all internal address books up-to-date as well.<br />

In addition, the users have an obligation to check the entries they use<br />

personally at regular intervals. This applies both to central address books and<br />

also to individual ones.<br />

Distribution lists are used by the fax server to route incoming fax<br />

transmissions to recipients. Incorrect entries in the distribution lists could<br />

result in unauthorised persons gaining access to fax transmissions containing<br />

confidential information. <strong>The</strong> fax mail centre should therefore check the<br />

distribution lists at regular intervals to ensure that they are up-to-date and<br />

intact.<br />

To ensure that address books and distribution lists are kept up-to-date, the fax<br />

mail centre must be informed when any member of staff leaves the<br />

organisation.<br />

To ensure that all administration work performed is traceable, all entries and<br />

alterations in central address books and distribution lists should be<br />

documented.<br />

Additional controls:<br />

- How often are address books and distribution lists checked to ensure they<br />

are intact and up-to-date?<br />

- How does the fax mail centre find out when a member of staff leaves?<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000<br />

<strong>Protection</strong> against<br />

manipulation<br />

Regular review of central<br />

address books<br />

Regular review of<br />

distribution lists

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!