we have been using disa ld 24 for a couple of decades and no abuse so far and no cost to set up. disa password can be 8 digits so hacking requires 100 million attempts. you would see these calls on cdr and know of the abuse.
Direct Inward System Access (DISA) allows selected users to access the
system from the public or private network by dialing a special Directory
Number (DN) assigned by the customer. The number can be dialed from any
Digitone telephone outside the network. Once the Direct Inward System
Access (DISA) call has been answered, the user can access any of the
following features and capabilities offered through Direct Inward System
Access:
• Calls to any station within the customer group
• Trunk calls (such as calls to a Public Exchange/Central Office, a TIE
trunk, or paging and dictation trunks)
• Basic/Network Authorization Code (BAUT/NAUT)
Page 154 of 1168 Direct Inward System Access
553-3001-306 Standard 14.00 August 2005
• Call Detail Recording (CDR) and Call Detail Recording Charge
Account, and
• Basic/Network Alternate Route Selection (BARS/NARS) and
Automatic Number Identification (ANI) route selection.
Each special Directory Number (DN) dialed by a DISA user is associated
with a particular DISA Directory Number. Any number of DISA DNs can be
assigned, provided that they are consistent with the numbering plan of the
customer. Access rights are determined by the Class of Service and Trunk
Group Access Restrictions (TGAR) associated with the DISA number. Calls
to DISA can be placed on dedicated, auto-terminate incoming trunks (Central
Office [CO], Foreign Exchange [FX], or Wide Area Telephone Service
[WATS]) and TIE or Direct Inward Dialing (DID) trunks, all of which must
have proper supervision.
As a safeguard against unauthorized use, an authorization code or special
security code of one to eight digits can be assigned for each DISA DN. The
security code must be entered before any system resources can be used.
Additionally, a secure data password can be provided to enable the customer
to create, modify, or remove information concerning DISA.