Technical information

Toll Fraud Job Aids
14-4 Issue 7 June 2001
Top 10 Tips to Help Prevent Phone
Phraud
1. Protect System Administration Access
Insure secure passwords exist for all logins that allow System
Administration or Maintenance access to the system. Change the
passwords frequently.
2. Prevent Voice Mail System Transfer to Dial Tone
Activate secure transfer features in voice mail systems.
Place appropriate restrictions on voice mail access/egress ports.
3. Deny Unauthorized Users Direct Inward System Access
(Remote Access)
If you are not using Remote Access features, deactivate or disable them.
If you are using Remote Access, require the use of barrier codes and/or
authorization codes set for maximum length. Change the codes frequently.
4. Place Protection on Systems that Prompt Callers to Input Digits
Callers should be prevented from dialing unintended digit combinations at
prompts.
Auto attendants and call vectors should be restricted from allowing access
to dial tone.
5. Use System Software to Intelligently Control Call Routing
Create ARS or WCR patterns to control how each call is to be handled.
Use Time Of Day routing capabilities to limit facilities available on nights
and weekends.
Deny all end-points the ability to directly access outgoing trunks.
6. Block Access To International Calling Capability
When international access is required, establish permission groups.
Limit access to only the specific destinations required for business.
7. Protect Access to Information Stored as Voice
Password restrict access to voice mail mailboxes.
Use non-trivial passwords and change passwords regularly.
8. Provide Physical Security for Telecommunications Assets
Restrict unauthorized access to equipment rooms and wire connection
closets.
Protect system documentation and reports data from being compromised.