No Audit Log entry for Template modifications
This seems very dangerous to me, not having an audit trail. A bad actor can, at will, make any changes to any template, then an innocent person using that template can cripple an organization and not know it. The likelihood is low I admit but it's not zero.The innocent then gets blamed because they are on the audit trail and the bad actor is not implicated in any way. This is a security hole and should not be an idea or suggestion that might or might not get implemented. Should be part of ISO9000 / HITRUST, IMOI’d even contemplate initiating an email notification at the modification of any template to the primary account 101. Maybe a checkbox if the customer wants it.
-
Elyse commented
Agree, I just discovered one of my templates was changed and confirmed with support there is no way to tell when it was changed and who did it. All I can see is successful application of the template. In this case I found the issue because someone had changed the template to where it did not overwrite any settings, and I was thus unable to apply it. I have templates for each of my offices that overwrite: caller ID, hold messaging, e-911 address, and presence. These are critical to our phone operations. If someone was changing settings in there for any reason whether malicious or careless, I don't really have any way to know.