S 2.48 Designating authorised fax operators
Initiation responsibility: IT Security Officer
Implementation responsibility: Internal Services
The authorisation for operating the fax machine must be restricted to a selected circle of reliable employees. These employees must be instructed regarding the proper handling of the machine and must familiarise themselves with the required security safeguards. Every authorised user should be informed about who may operate the fax machine and who is the person in charge of the Fax System. Furthermore, clearly written operating instructions should be available at the fax machine.
By restricting the circle of fax operators to the minimum number required for operative use, the number of persons who may read incoming fax transmissions is limited.
Review questions:
- Has the authorisation for operating the fax machine been restricted to a selected circle of reliable employees?
- Have the employees authorised for operating the fax machine been instructed on how to properly handle the fax machine and familiarised with the required security safeguards?
- Are clearly written operating instructions available at the fax machine?