Technical information
Tools that Restrict Unauthorized Outgoing Calls
Issue 7 June 2001
4-25
Security Tips
PSA/TTI transactions are recorded in the history log, which can be accessed by
entering the list history command at the prompt. If there is a concern about
unauthorized PSA/TTI usage, refer to the history log for verification. To enable
recording PSA/TTI transactions, access the Feature-Related System Parameters
form by entering the change system-parameters features command at the
prompt. Then ensure that the “Record PSA/TTI Transactions in History Log” field
is set to y. (Sometimes this flag is set to n if PSA/TTI entries tend to flood the
history log, therefore making it difficult to find other entries.) The default for the
field is y.
A COS for the user’s extension must be administered to have access to PSA.
However, be sure to limit PSA COS assignments to stations that need to access
PSA.
Once a PSA station is associated with a terminal, anyone using that terminal has
all the privileges and capabilities of that station. Therefore, use of the dissociate
Facility Access Code (FAC) is recommended whenever the terminal is not in use.
If PSA and DCP extenders are used to permit remote DCP access, the security
provided may not be adequate. A user connecting via DCP extenders must
provide a password. However, once the user is connected, the remote DCP
station has the capabilities and permissions of whatever station is associated or
merged with the local DCP extender port unless the station has been dissociated
or separated. Therefore, PSA users should dissociate before they disconnect
from a DCP extender.
PSA security violations are recorded by SVN software, if enabled. Refer to the
SVN feature description and to the DEFINITY ECS Release 5 Feature Description
and to DEFINITY ECS Release 5 Implementation for security report information.
Extended User Administration of Redirected
Calls
This feature allows station users to select one of two previously administered call
coverage paths assigned to them (for example, a work location coverage path or
a remote work location coverage path) from any on-site extension or from a
remote location (for example, home). Also provided is the ability to activate,
change, or deactivate Call Forward Add or Call Forward Busy/Don’t Answer from
any on-site extension or from a remote location.
For security purposes, each user of this feature is administered a SSC. Users
must enter an SSC to use this feature. In addition, the COS and COR for the
user’s extension must be administered to have access to this feature. Any attempt
by an invalid extension or invalid SSC to use the feature is recorded as a security
violation.