23.12.2014 Views

official publication of the washington bankers association - Media ...

official publication of the washington bankers association - Media ...

official publication of the washington bankers association - Media ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Serving The Needs Of Washington Bankers Since 1889<br />

Information Privacy and Legal Compliance for Your Email Communications<br />

What You Need to Know About<br />

Email Encryption and Archiving<br />

by John Pelley, CISSP, ISSAP, MBCI, Redhawk Network Engineering, Inc.<br />

Build Trust in Your Email Communications with<br />

Email Encryption<br />

Assure your clients, partners, and employees that emails tagged to contain<br />

sensitive data will not be visible to prying eyes. Today’s email encryption<br />

technology provides an easy-to-use secure communication channel to<br />

encrypt both outgoing email and replies, even if your recipient doesn’t have<br />

an encryption strategy in place.<br />

Email encryption in <strong>the</strong> market today includes onsite appliances that<br />

your organization can self-manage. The latest industry direction involves<br />

outsourced, cloud-based solutions or S<strong>of</strong>tware-as-a-Service (SaaS) email<br />

encryption. Cloud-based services make sense, because email is carried on<br />

<strong>the</strong> Internet while in transit. A cloud service can provide multiple email<br />

services from high availability facilities with pr<strong>of</strong>essional 24/7/365 administration,<br />

monitoring and support.<br />

• Protect Your Assets with Encryption - Defined policies will shield<br />

sensitive company data from open Internet exposure. email encryption<br />

protects your sensitive email data from being transmitted<br />

outside <strong>the</strong> network.<br />

• Comply with Data Privacy and Security Regulations with Encryption<br />

- Use email encryption to comply with GLBA, Sarbanes-Oxley<br />

and PCI guidelines.<br />

for archiving. The documented email archiving policy and procedure<br />

must be adhered to. Your retention period could be from one<br />

to seven years. Management will need to decide <strong>the</strong> time period and<br />

include it in <strong>the</strong> policy.<br />

• An email archiving and storage solution utilizing ei<strong>the</strong>r selfmanaged<br />

or outsourced technology. Email data must be archived<br />

to write-once media with <strong>the</strong> stated retention policy.<br />

With a reasonably priced solution and a documented policy, your organization<br />

can reach an improved level <strong>of</strong> privacy compliance and improve its<br />

legal position.<br />

For more information and compliance questions, please contact John Pelley , CISSP,<br />

ISSAP, MBCI - Redhawk Network Engineering, Inc. 541-382-4360 extension 102,<br />

email:john@redhawksecurity.com. For more about email security solutions please visit<br />

<strong>the</strong> Redhawk website at www.redhawksecurity.com<br />

Improve Your Security and Legal Posture with Hosted<br />

Email Archiving<br />

Email archiving works with your email system to enable you to store, search<br />

and recover email when needed.Why archive email<br />

• To secure mission critical data with <strong>of</strong>fsite storage for disaster<br />

recovery – Offsite storage <strong>of</strong> your business communications is a<br />

necessary component <strong>of</strong> a disaster recovery plan. A hosted archive<br />

solution will mitigate <strong>the</strong> risk <strong>of</strong> losing critical communications.<br />

• Establish an email archiving program and improve your legal<br />

posture – if your organization does not meet <strong>the</strong> legal criteria for archiving,<br />

email may not be admissible in court. Your defense against<br />

email content brought into litigation may also be compromised.<br />

Elements <strong>of</strong> an Effective Email Archiving Program<br />

Email is legally admissible as a business record when a consistently applied<br />

method is utilized for archiving and storage. This approach complies with<br />

<strong>the</strong> chain <strong>of</strong> custody and rules <strong>of</strong> evidence legal precedents. A strong legal<br />

posture is achieved by:<br />

• A documented policy with stated retention period and procedures<br />

23<br />

July/August 2011 ⏐

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!