Skip to content
AI Dialer

Glossary · Voice technology

What is DISA (direct inward system access)?

  • Also called: direct inward system access

Reviewed by Sujan ThapaliyaLast updated

Definition

DISA lets an authorised caller dial into a phone system from outside, authenticate, and then place outbound calls as if they were on the internal system. It was widely used before mobile plans made it unnecessary, and it is now mostly a security liability.
The three STIR/SHAKEN attestation levels, which underpin how disa (direct inward system access) behaves in practice: A asserts both that the carrier knows the customer and that the customer may use the calling number, B asserts the customer only, and C asserts neither. A shared number pool can reach B at best, which is why number ownership keeps recurring in these definitions.
Attestation is the backdrop to most caller-ID and deliverability terms, disa (direct inward system access) included.

In practice

How disa (direct inward system access) actually works

Poorly secured DISA is one of the classic routes to toll fraud: an attacker who guesses the PIN can dial premium international destinations on your account, often overnight and at a cost measured in tens of thousands.

If you do not have a specific reason to run DISA, disable it. If you do, use long PINs, restrict source numbers, and cap international destinations.

Where a genuine need for DISA survives, it is usually cost-driven — dialling out through the office system to avoid international charges from a mobile. Every one of those cases is better solved by a softphone, which authenticates properly, logs the call against a user, and does not expose an inbound door to the public network.

Worked example

A DISA line protected by a four-digit PIN is 10,000 combinations, which an automated dialer exhausts overnight. That is the whole attack, and it is why the feature is disabled on most modern systems.

DISA (direct inward system access): common questions

What is DISA used for?
Letting an authorised person dial into the phone system from outside and then dial out through it, so the call presents the company's number. It predates mobile roaming and softphones, which have made most of its legitimate uses obsolete.
Why is DISA a security risk?
Because it is a doorway from the public network into your outbound dialing, usually protected by a short PIN. A compromised DISA line is one of the classic routes into toll fraud, and the bill arrives before anyone notices.
Should DISA be disabled?
On almost every modern system, yes. A softphone gives an authorised user the same outcome with authentication that is actually worth something, and turning DISA off removes an entire class of fraud.

Sources

  1. Combating Spoofed Robocalls with Caller ID AuthenticationFederal Communications CommissionThe STIR/SHAKEN framework, the attestation levels carriers sign calls with, and the mandate requiring providers to authenticate caller ID.
  2. 47 U.S.C. § 227 — Restrictions on the use of telephone equipmentCornell Legal Information InstituteThe Telephone Consumer Protection Act itself — the consent requirements, calling-hours limits, and private right of action.
  3. ITU-T Recommendation E.164 — The international public telecommunication numbering planInternational Telecommunication UnionThe international number format, the 15-digit maximum, and how country codes and national numbers compose.

See disa (direct inward system access) in the product

A hosted PBX is a business phone system that runs as software in a provider's data centre instead of a box on your premises. Handsets and softphones register to it over the internet, and capacity, extensions and numbers change in configuration rather than by an engineer visit.