O Generic RAS Countermeasures

Always maintain an updated, detailed map of the phone lines that connect to your physical or virtual assets (including X.25 addresses). Just as anyone responsible for physical security would be required to know the location of every entrance into the "brick and mortar" company, those responsible for information security should know all the channels through which information will enter or leave the company.

Security policies should also require that employees be familiar with common social-engineering techniques and emphasize that usernames and passwords are privileged and confidential information.

