Appendix A: Customer Support Information

Security Risks Associated with the Automated
Attendant Feature of Voice Messaging Systems

Two areas of toll fraud risk associated with the Automated Attendant feature of voice messaging systems are:

Remote Call Forwarding can be used securely only when the central office provides "reliable disconnect" (sometimes referred to as forward disconnect or disconnect supervision), which guarantees that the central office does not return a dial tone after the called party hangs up. In most cases, the central office facility is a loop-start line/trunk which does not provide reliable disconnect. When loop-start lines/trunks are used, if the calling party stays on the line, the central office does return a dial tone at the conclusion of the call, enabling the caller to place another call as if it were being placed from your company. Ground-start trunks provide reliable disconnect and should be used whenever possible.

Preventive Measures

Take the following preventive measures to limit the risk of unauthorized use of the Automated Attendant feature by hackers:



Topics
  Support Telephone Number
  Federal Communications Commission (FCC) Electromagnetic Interference Information
  Canadian Department of Communications (DOC) Interference Information
  FCC Notification and Repair Information
  Installation and Operational Procedures
  DOC Notification and Repair Information
  Renseignements sur la Notification du Ministère des Communications du Canada et a Réparation
  Security of Your System: Preventing Toll Fraud
  Toll Fraud Prevention
 
  Physical Security, Social Engineering, and General Security Measures
Security Risks Associated with Transferring through Voice Messaging Systems
Security Risks Associated with the Automated Attendant Feature of Voice Messaging Systems
Security Risks Associated with the Remote Access Feature
  Other Security Hints
 
  Educating Users
Educating Operators
Detecting Toll Fraud
Establishing a Policy
Choosing Passwords
Physical Security
Limiting Outcalling
  Limited Warranty and Limitation of Liability
Remote Administration and Maintenance