19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Safeguard Catalogue - Organisation Remarks<br />

____________________________________________________________________ .........................................<br />

S 2.27 Dispensing with remote maintenance of the<br />

PBX<br />

Initiation responsibility: Head of <strong>IT</strong> Section; <strong>IT</strong> Security Management;<br />

PBX officer<br />

Implementation responsibility: -<br />

Dispensing with remote maintenance is an effective measure to prevent<br />

external persons from manipulating the PBX installation configuration. For<br />

individual installations and small networks of interconnected installations with<br />

short spatial distances between their individual members, this approach is<br />

expedient also for economic reasons.<br />

Advantage: As opposed to all other measures listed in Part I, Chapter 8.1<br />

Telecommunications System (Private Branch Exchange), this approach can<br />

ensure that access to the servicing port of the installation will be precluded<br />

even in case of direct access to the lines of the Telekom. Otherwise, a similar<br />

degree of security could only be achieved with the help of cryptological<br />

means.<br />

Disadvantage: All maintenance work must be carried out directly on the<br />

facility. Failing any additional measures, e.g. removal of the maintenance PC<br />

to the adjacent room, the maintenance staff will always have access to the<br />

PBX facility as well. <strong>The</strong> remote interfaces are often not only used for remote<br />

maintenance. Remote signalisation needed for the operation of the PBX<br />

network is occasionally carried out via the same interfaces. In such cases,<br />

dispensing with remote maintenance would mean dispensing with central<br />

network management. If a remote interface is only to be used for remote<br />

signalisation purposes via modem, this modem should be configured in such a<br />

way that calls cannot be received.<br />

Additional controls:<br />

- Which reasons speak for and which reasons speak against the<br />

relinquishment of remote maintenance?<br />

- Has a corresponding decision on remote maintenance been made?<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!