BharatBhasha.com
 
Free Articles  >>  Email >>  Page 6  >> 

E mail Security Governance E mail Encryption and Authentication as a Business Enabler

E-mail Security Governance: E-mail Encryption and Authentication as a Business Enabler   by CipherTrust

How to Easily Secure Your E-mail System and Comply with HIPAA, Sarbanes-Oxley, and GLBA Regulations



While recent government regulations vary in scope and purpose, the need to protect and ensure the integrity of information is universal. Much of the information germane to business today is assimilated and communicated over messaging platforms such as e-mail. As a result, the need for a comprehensive approach to the secure delivery of e-mail affects almost all organizations, regardless of industry or size. As with many management challenges, the unknown is the most significant cause for concern. In the case of e-mail and messaging security, the most ominous threat is often the lack of ability to measure information flowing in and out of the corporate e-mail network.

E-mail has traditionally been sent “in-the-clear,” meaning that e-mail headers and contents have been readily accessible to anyone with the ability to monitor network traffic. Traditionally, encryption technologies have been sufficiently difficult to implement that many businesses chose to sacrifice security in the name of user-friendliness given an application as mission-critical as e-mail. For example, some encryption and authentication technologies require ubiquitous adoption by each entity attempting to communicate, and few have ever agreed on which technologies are best or most efficient. Many businesses, committees and users have been attempting to standardize such use for well over a decade.

Over the last few years, however, regulations have been enacted that require the business and technology communities to generate and implement secure e-mail solutions. Easy-to-use encryption and authentication are now readily available. The new challenge for the enterprise is to determine where and how to implement these new solutions to ensure compliance with new regulations. Understanding how each regulation affects e-mail security and delivery is important to understanding the pressures all IT managers will be under in the months and years to come.

E-mail Security Issues for Sarbanes-Oxley



The Sarbanes-Oxley Act of 2002 took effect in June of 2004 and requires CEOs, CFOs, independent auditors and audit committees to certify the accuracy, confidentiality, privacy and integrity of financial statements -- and the effectiveness of internal controls and procedures for financial reporting and disclosures. The most relevant sections of Sarbanes-Oxley to e-mail security are sections 404 and 802.

  • Section 404 deals with internal controls, and requires organizations to implement controls over the release of information to individuals or organizations outside the company’s network.
  • Section 802 addresses records management, and how long and in what manner documents (including e-mail) should be retained.


Sarbanes-Oxley does not detail specific steps organizations should take to comply with these regulations. Rather, it requires that companies implement programs that ensure the secure flow of information, and then to be able to document the success and deficiencies of those programs. There exist some programs that are commonly used as a basis for implementation.

Corporations and business partners of companies affected by Sarbanes-Oxley, are required to ensure that sensitive information remains secure. Similar to HIPAA solutions, “Insider information” should not be accessible outside of the perimeter of a company’s network. Encryption policies should be enforced whether a busy executive remembers to encrypt a message or not. Rogue employees should not be capable of transmitting sensitive financial information outside the network. Detailed reports should be available to auditors showing how the system has successfully protected the network and archived relevant communications. All of this can be handled swiftly with an e-mail governance policy and a central implementation mechanism. Without a mechanism in place, these requirements create a tangled web of complicated transactions and increased risk.

Unlike HIPAA, however, Sarbanes-Oxley often creates a need for organizations to prevent end-user encryption of information because encrypted information cannot be filtered for inappropriate content or trade secrets as it moves through the e-mail servers and onto the Internet. E-mails should be sent to the server as clear-text, and only once the content has been cleared for release should it be encrypted according to the organization’s policies.

The need to enforce centralized content policies, as well as the need to provide detailed reports to audit committees, requires server-level control and administration. The servers should be flexible in terms of encryption technology in order to maximize the utility of e-mail, while at the same time the network should be defended from external attacks

E-mail Security Issues for HIPAA



The Health Insurance Portability and Accountability Act (HIPAA) came into effect on April 21, 2003. The act is designed to protect the confidentiality, integrity, and availability of Protected Health Information (PHI) for individuals. PHI is defined as information that includes any individually identifiable health information. Healthcare organizations that must comply with HIPAA regulations are known as Covered Entities (CEs). CE’s include hospitals, insurance providers, employer health plans, physicians, business partners, and contractors working with healthcare providers.

The primary rule within HIPAA that affects e-mail is the Security Rule. Exposed PHI within e-mail is considered a risk that will surface during a HIPAA risk assessment. Covered Entities are required to perform a HIPAA risk assessment and then to adopt appropriate safeguards depending upon the outcome of the assessments they perform.

Healthcare organizations have reacted to the new rule in a variety of ways, and with varying degrees of effectiveness. The efficiency of e-mail offers an attractive means to transmit healthcare information from one organization to another; however the need to secure each transmission of PHI has created complications as secure e-mail solutions are new and not fully implemented at many sites that transmit and store PHI.

Many encryption technologies require the user to become familiar with the use of plug-ins and other specialized “client-side” encryption software. Encryption keys must be securely traded between partners, patients, providers, and other network members. More and more employees are involved in transmitting PHI over the internet now than ever before. The increase in the number of employees transmitting PHI has caused administrative costs to increase as the need to train employees in proper use of encryption technologies also increases.

As the complexity increases, so does the probability that not all e-mail containing PHI will be encrypted. Doctors, who are always pressed for time, may not take the extra few minutes required to encrypt an e-mail. The clerk handling outbound messages for a nurse may not understand which information requires encryption and which does not. Furthermore, many healthcare administration workers have not been trained on the identification of PHI and subsequent proper handling.

The uncertainties and potential liabilities have led some organizations to go so far as to outlaw all PHI in e-mail. Instead of solving the problem, however, these decisions generally force employees to find alternative, and usually insecure, methods of transmitting PHI via e-mail in order to accomplish their jobs. This leaves organizations vulnerable to lawsuits based, at best, on non-compliance with HIPAA and, at worst, exposed PHI. The liability is tremendous – leading many insurance providers to be extremely hesitant to provide coverage in the IT space unless sound security practices and compliance can be proven.

The same problems arise with client-based encryption technologies that require the user to be trained or to take extra time to accomplish his or her task. The effect is an increase in likelihood that PHI will be transmitted through an insecure channel as rushed or untrained employees break policies set up to protect information.

Another issue faced by organizations is a lack of technological standards. Some organizations may be employing technologies such as S/MIME or PGP encryption, while others utilize secure connection technologies such as TLS or HTTPS. The effect is that any two organizations, each complying with HIPAA regulations in their own way, may be unable to communicate electronically due to a lack of standardization within the industry.

The solution to each of these issues is to move the encryption responsibility from the individual user to a specialized server, and to utilize a system that can select from a number of encryption technologies depending on the recipient’s technological capabilities. The server should be capable of applying encryption policies based on heuristics determined by the security officer, administrator, or business rules. Individual users should be able to specify that a message be encrypted, but the encryption should automatically be applied where appropriate regardless of user involvement.

Beyond encryption issues, CE's need to maintain system integrity, and availability of information. At all times, the network should not be at risk of downtime due to hacking attempts, Denial of Service (DOS) attacks, spam attacks, phishing, social engineering, or viruses.

E-mail Security Issues for Graham-Leach-Bliley Act



The Graham-Leach-Bliley Act (GLBA) was signed by Bill Clinton in 1999 and made fully effective on July 1, 2001. GLBA requires financial institutions, partners and contractors to protect consumer’s private financial information. It is similar in purpose to the HIPAA regulations governing the use and transmission of information in the healthcare industry. It also imposes many of the same challenges on the financial industry as those faced by the healthcare industry.

As with organizations affected by HIPAA and Sarbanes-Oxley regulations, financial institutions are faced with the need to protect confidential data, comply with regulations, keep the network operational and secure, and operate on a budget. The consequences of a failure to perform in any of these areas could result in imprisonment of company officers and fines. It could also have devastating effects on the business itself – potentially causing existing and potential customers to lose faith in the company’s ability to service their financial needs.

As with healthcare organizations and corporate entities, the need to establish centralized policy-based governance over the transmission, encryption, and archival of sensitive information requires a secure server-based solution. The solution should be capable of interfacing with all of an organization’s business partners regardless of the partner’s technological capabilities, and it should be transparent to the user in order to maximize the efficiency and utility of e-mail and encourage adoption of acceptable means of corporate communication.

Conclusion



The trend is clearly in the direction of more complex security regulations and an increasing concern by consumers and investors over an organization’s ability to protect privileged information. Fortunately, this increasing awareness of the general public and government agencies has coincided with a rapid development of the technologies required to meet these demands. CipherTrust has led the e-mail security industry in developing comprehensive solutions to e-mail borne threats such as spam, hackers, phishing, DOS attacks and more.

CipherTrust’s IronMail provides the first true balance of security and usability that will enable businesses to protect the confidentiality and integrity of information as required while ensuring that employees can continue to use e-mail easily as a central communication medium. IronMail enables e-mail security governance with ease, solving a problem that has plagued the industry for 15 years.

Others merely claim it. IronMail does it. We invite you to try it. Click here to schedule a FREE online demonstration of IronMail.

CipherTrust manufactures the leading Enterprise E-mail Security appliance, IronMail. To learn more about how IronMail can help your organization filter spam, block attacks, and prevent fraud, download our white paper, "Controlling Spam: The IronMail Way."

Stay up to date on all E-mail security issues by signing up for the IronMail Insider Newsletter.




Article Source: http://www.BharatBhasha.com
Article Url: http://www.bharatbhasha.com/email.php/18035

Other Articles related to "E mail Security Governance E mail Encryption and Authentication as a Business Enabler" by CipherTrust

How HIPAA Security Policies Affect Corporate E mail Systems
by CipherTrustAlthough considered by many to be the sole concern of health care providers, the Health Insurance Portability and Accountability Act (HIPAA) affects nearly all companies that regularly transmit or store employee health insurance information. HIPAA was signed into law in 1996 and it's original purpose was to protect employee health and insurance information when workers changed or lost their jobs. As use of the internet became more widespread in the mid-1990s, HIPAA requirements...

Maximizing E mail Security ROI Part V A New Twist to an Old Problem Email Encryption
by CipherTrust This is the last of a five-part series on Maximizing Email Security ROI. Throughout the ages, people have encrypted communications to suit their information security needs. In the 1st century B.C., Julius Caesar didn’t trust the couriers who carried his messages to trusted acquaintances. So, he replaced every A with a D, every B with an E, and so on, all the way through the alphabet. Only those who knew Caesar’s shift-by-three rule could decipher his messages. Over 2000 years...

Maximizing E mail Security ROI Part IV The Digital Monsters under Your Bed E Mail Intruders
by CipherTrust This is the last of a five-part series on Maximizing Email Security ROI. Remember your kid fears? As soon as the lights went out, the monsters under your bed began plotting ways to get you. Somehow, though, you always managed to outsmart them and make it through the night. Then one night you grew up, and the monsters went away for good. Well, they're back. And they've unionized.International rings of hackers, many backed by funds from organized crime groups, are the new...

Detecting and Eliminating Computer Viruses at the Gateway
by CipherTrustTraditional anti-virus software only stops known computer viruses – stopping undefined computer viruses requires a different approach.In the past, network administrators scrambled to apply new virus signatures whenever new computer viruses were discovered. While these signatures will stop a known threat, it takes time for anti-virus vendors to develop them. Unfortunately, the newest and most damaging viruses are able to spread so quickly that the damage is done before a...

Maximizing Email Security ROI Part III No More Mr Nice Guy Enforcing E Mail Policy
by CipherTrustThis is the third of a five-part series on Maximizing E-mail Security ROI.E-mail is an easy, cheap and readily available form of communication. It’s a great tool for businesses, but without proper safeguards in place to regulate the information transmitted it can also be a potential threat. An effective e-mail policy should be all-encompassing, helping organizations comply with federal regulations, protect intellectual property and prevent offensive materials from being...

Increase Efficiency with Intelligent Email Traffic Control
by CipherTrustWork Smarter, Not HarderCipherTrust’s IronMail has helped some of the largest enterprises in the world stem the flood of spam to their end users, as well as address a host of other e-mail threats. IronMail’s unique Spam Profiler tool provides maximum effectiveness by scrutinizing thousands of characteristics of every message to determine a spam score. But the challenges for enterprises today do not stop at identifying and blocking spam. With spam volumes continuing to increase...

Maximizing Email Security ROI Stop Spam and Save
by CipherTrustThis is the first of a five-part series on Maximizing Email Security ROI In the realm of email security threats, the costs of spam are relatively easy to recognize. Although most organizations rarely, if ever, take the time to calculate their spam costs, they can easily account for the losses caused by spam with regards to employee productivity, consumption of IT resources and help desk costs. Harder to measure are the less obvious, and potentially catastrophic, costs incurred...

3 Criteria for Controlling Enterprise Spam
by CipherTrustOr: T*ake Y O U R email ba & ack + From the Sp@mmers! 0400constrictor bubble snake informational If you have a business, then you have a spam problem. The efficiencies of communicating through e-mail not only benefit organizations like yours; they also benefit the spammers who profit off of sending pernicious e-mails to millions of people every day. In fact, spam is so cost-effective that it costs less than $0.0004 to send a single spam. That’s 25 emails for just one penny! The...

How Spammers Fool Spam Filters
by CipherTrustAnd How to Stop Them Effectively stopping spam over the long-term requires much more than blocking individual IP addresses and creating rules based on keywords that spammers typically use. The increasing sophistication of tools spammers use coupled with the increasing number of spammers in the wild has created a hyper-evolution in the variety and volume of spam. The old ways of blocking the bad guys just don’t work anymore. Examining spam and spam-blocking technology can...

Does Your Email Reputation System Have a Bad Rep
Does Your Email Reputation System Have a Bad Rep?   by CipherTrustThe recent spike in the volume of spam traveling across the Internet, combined with the dangers of phishing and virus attacks that frequently accompany these messages, has forced enterprises to reconsider how they determine which messages will be allowed into their network. The latest advances in anti-spam technology have been enabled in part by the use of reputation services which determine the “good” and “bad” senders. There...

Click here to see More Articles by CipherTrust
Articles In LimeLight
  • Think Green While Cleaning
    By Markus Skupeika Added on Thursday, April 17, 2008
  • Clean Kitchen 101
    By Markus Skupeika Added on Thursday, April 17, 2008
  • Internet Marketing Network Company Helps Clients Grow
    By D.H. Cannon Added on Thursday, April 17, 2008
  • Virtual Credit Cards: Pranksters And Cheaters Take A Walk
    By Devin Gilliland Added on Thursday, April 17, 2008
  • Is Chiropractic Care During Pregnancy Right For You?
    By Connie Limon Added on Thursday, April 17, 2008
  • Guide To The New Google Algorithm You Can't Afford To Ignore
    By Moe Tamani Added on Thursday, April 17, 2008
  • PC200 Spiral Coil Binding Machine Product Review
    By Jeff McRitchie Added on Thursday, April 17, 2008
  • Make Money Online : How To Choose The Best Program To Make The Most
    By Alan Lim Added on Thursday, April 17, 2008
  • Go Organic In Household Cleaners
    By Markus Skupeika Added on Thursday, April 17, 2008
  • Egg Salad Surprises
    By Low Jeremy Added on Friday, April 18, 2008
  • Heal Your Home And Get Rid Of Mold
    By Markus Skupeika Added on Friday, April 18, 2008
  • Debt Management Advice
    By Carrie Reeder Added on Friday, April 18, 2008
  • The Phenomena Of Sales Leads
    By John Le Papillon Added on Thursday, April 17, 2008
  • Home & Household LED Light Bulbs Discount Sales
    By Camille Howe Added on Friday, April 18, 2008
  • Clean Your Home With Just One Multi-Purpose Cleaner
    By Markus Skupeika Added on Thursday, April 17, 2008
  • How To Fund Business Startups
    By Zachary Thompson Added on Friday, April 18, 2008
  • The Citronella Dog Collar - A Natural Way For Controlling A Dog's Barking
    By Lee Dobbins Added on Thursday, April 17, 2008
  • Adult ADD: Forget The Yak Butter Tea
    By Tellman H. Knudson Added on Thursday, April 17, 2008
  • Taking Care Of Your Wood Floors With Floor Wax
    By Adam Peters Added on Thursday, April 17, 2008
  • The Logic Behind Training Evaluation
    By Sam Miller Added on Friday, April 18, 2008
  • About Author CipherTrust :

    CipherTrust is the leader in anti-spam and email security. Learn more by downloading our free whitepaper, “Securing the E-mail Boundary: An overview of IronMail” or by visiting www.ciphertrust.com.

    Publishers / Webmasters
    Tell A Friend
    Comments / Questions?
    Download this article in PDF
    Search through all the articles:


    210 Users Online!
    Related Articles:
    Latest Articles:
     
    Email >> Top 50 Articles on Email >> All Articles in this category
    Category - >
    Advertising Advice Affiliate Programs Automobiles
    Be Your Own Mentor Careers Communication Consumers
    CopyWriting Crime Domain Names DoT com Entrepreneur Corner
    Ebooks Ecommerce Education Email
    Entertainment Environment Family Finance And Business
    Food & Drink Gardening Health & Fitness Hobbies
    Home Business Home Improvement Humour House Holds
    Internet And Computers Kiddos and Teens Legal Matters Mail Order
    Management Marketing Marriage MetaPhysical
    Motivational MultiMedia Multi Level Marketing NewsLetters
    Pets Psychology Religion Parenting
    Politics Sales Science Search Engine Optimization
    Site Promotion Sports Technology Travel
    Web Development Web Hosting WeightLoss Women's Corner
    Writing Miscellaneous Articles Real Estate Arts And Crafts


    Disclaimer: The information presented and opinions expressed in the articles are those of the authors
    and do not necessarily represent the views of Bharatbhasha.com and/or its owners.


    Copyright © AwareINDIA. All rights reserved || Privacy Policy || Terms Of Use || Author Guidelines || Article Search
    FAQs Link To Us || Submit An Article || All Products || Free Downloads|| Contact Us || Site Map  || Advertise with Us ||
    Click here for Special webhosting packages for visitors of this website only!