Toll Fraud Security and DISA

Most businesses Telephone Systems have ato you that DISA is not active. This means your
feature called Direct Inward System Access ortechnician must show you on the computer that
DISA for short. This feature allows authorizedthis feature is either not available or that it has
users to dial a special number into your telephonenot been programmed for any reason. This should
system and then either dial extension numbersbe checked at least once a year.3) If your
directly or outside numbers utilizing yourtelephone system allows an outside line to be
company's less expensive long distance trunksconnected to another outside line without or
and services.A word of advice: If you are usingwithout internal supervision, carefully consider why
DISA - Stop it!There is a tremendous security riskyou need this feature. There may be perfectly
associated with DISA that could cost yourvalid reason to forward external callers to outside
company thousands of dollars. As far as your longlines but you should closely evaluate your options.
distance provider is concerned, you areIf you decide you do not need this feature, not
responsible for the cost of any call originatingonly you're your service provider disable it, but
from your telephone system even if the call isalso work with your technician to have them
fraudulent.Ideally, this is how DISA works:Anprove to you it has been disabled. This may mean
authorized external caller or employee needs tohaving the technician set the feature up,
call a customer that would be a long distance call.demonstrate how it works, disable it and
Rather than paying for the long distance call ondemonstrate how it no longer works.4) Be sure
their bill, he or she dials into your PBX, enters ayour Voice Mail system does not have a Class Of
security code then dials his long distance call. TheService or Class of Restriction that allows it to
call then uses your long distance carrier and thetransfer callers or even make outside calls. Some
caller does not have to expenses back the call. Invoice mail systems have the ability to transfer
most cases the call is cheaper this way also.But incallers to outside telephone lines. Again outside
the real world it really works like this:Someonetransfers should be blocked. But also there is
finds or acquires your DISA number by one ofoften requirements for voice mail to alert cell
several means: shoulder surfing, finding documentsphones that a message has arrived in the users
careless about or by one of several softwarebusiness telephone mailbox. If you use cell phone
programs designed to find such things. A workingmessage waiting notification, be sure to verify
account code is discovered using the samewith your PBX or key system service provider
methods. Once a valid number is found, the callerthat all ports on the voice mail system only have
has nearly unlimited access to your long distancethe ability to call within your local zone. There is
services.Many times this information is used to settypically no reason for any port on a voice mail
up "call centers" that will use your system to allowsystem to have the ability to make international
people to make calls to whatever county theyor even national calls. Again, and I stress this, be
like. These calls can add up to thousands of dollarssure to have your service provider prove these
in a very short period of time - even as short asthings to you.5) Basic telephone system toll fraud
a day or weekend your company is on the hooksecurity audits should be done at least once a
for the cost.In this day and age we must also beyear. Often, many different people will be
concerned with terrorism. No one wants to beprogramming in your system, activating and
the medium that allows terrorist to communicate.deactivating features. These individuals each come
But certainly that is a real possibility and the callswith varying degrees of skills and security
becomes more difficult for National Security toconcerns. It is imperative that you as a business
track.Since the early years of my career, I haveowner or someone responsible for your telephone
seen at least one case personally, and heard ofsystem verify that proper security measures
many others, where a PBX technician set up ahave been take.Remember this when asking for a
DISA number and authorization code and turnednew feature: even though you may not be aware
the customers PBX into his own personal longof a feature that compromises your service, you
distance service. In this case, the cost may beare still responsible for the bills - even the
minimal but you are still paying for the call.Herefraudulent calls. Therefore always ask your
are my specific recommendations for telephoneservice personnel if what they are doing may
system owners.1) If you are using DISA - switchcompromise security in anyway. Not only does
to prepaid calling cards or (and especially) if thethis question help you understand the toll fraud
user is making calls from his or her home office,security risk involved in what you are asking your
offer a monthly stipend for long distance service.technician to do, but it will also make your
Residential long distance service can be found fortechnician more conscience of the fact that you
as little as 1.6 cents per minute and cost ofare expecting him or her to ensure security.Ralph
prepaid calling cards has fallen dramatically. NowNelson Willett is a Voice Telecommunications
the risk is limited to the cost of the card. YouSpecialist with over 20
could also considering adding a VoIP line to theyears in the industry.
uses home for as little as $20 per month.2) HaveVisit for more.
your telephone system service provider PROVE