Home > Midmarket CIO Tips > > 10 steps to a holistic secure messaging strategy: Check IT List
CIO Midmarket Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 


10 steps to a holistic secure messaging strategy: Check IT List


Crystal Ferraro
10.28.2003
Rating: --- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


This tip originally appeared on SearchSecurity.com, a sister site of SearchSMB.com.


Insecure messaging comes with a host of dangers including data loss, theft and leakage, compromised systems, downtime and loss of productivity. Unfortunately, secure messaging is no longer as straightforward as keeping the latest virus from entering an organization via e-mail. At Information Security magazine's Security Decisions conference Jim Reavis, president of Reavis Consulting Group, outlined 10 steps for a holistic secure messaging strategy. Here are the highlights.

  1. Implement enforceable policies that users understand. Policies should clearly communicate acceptable and appropriate usages with clear definitions and examples. Users should know what is good behavior and what is bad behavior, Reavis said.

  2. Build your messaging architecture to allow for granular rules control. "We need agility in our networks and messaging systems," Reavis said. By compartmentalizing you can improve incident response and provide limited service during an incident.

  3. Develop a formalized computer emergency response team (CERT) and incident response plan specific to messaging incidents. A specialized messaging response team should focus on containment, disinfection, remediation and rebuilding systems.

  4. Create an awareness program to strengthen your last line of defense -- your users. Include courseware such as PowerPoints or Flash to reinforce policy and educate about threats and safe practices. Tell users what to do in case of an incident and where to go for help. Make it easy for users to report incidents via the company intranet. If the reporting procedure is difficult or makes users feel dumb, they won't report.

  5. Maintain a baseline and continuous measurement system of your network. "If you don't understand how your network operates, you don't understand your business," Reavis said. This includes network traffic analysis, e-mail and IM logging and trend analysis.

  6. Increase your organization's use of encryption. While encryption is virtually unbreakable, most organizations only encrypt 1% of all messages, Reavis said.

  7. Proxy all connections, including peer-to-peer applications such as instant messaging. You can also do e-mail encryption by proxy, Reavis said. An encryption proxy sits on the network between the e-mail server and the Internet. The proxy manages keys, encrypts messages and gives the recipient the option of a secured SMTP message or Webmail.

  8. Deploy multiple layers of virus/spam protection. There are five possible antivirus scanning points: e-mail client, e-mail server, antivirus gateway, network layer antivirus appliance and a managed security service provider. Reavis recommended using three of these five points and using two different vendors.

  9. Deploy best-of-breed solutions. "This is where the industry is right now. Integrated suites are very immature and don't provide adequate security," Reavis said.

  10. Finally, take an integrated team approach to securing your organization's messaging systems.

Do you have comments on this tip? Let us know.


Rate this Tip
To rate tips, you must be a member of SearchCIO-Midmarket.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Information security management for the midmarket
Droid does, but will IT support it?
Information security program revamp adds outsourcer oversight and more
From data breaches to risk management frameworks: Test your knowledge
The challenge of managing risk when IT budgets tighten
Why cybersecurity awareness is everyone's responsibility
Information technology management e-book downloads for midmarket CIOs
10 must-have steps for an effective SMB information security program
Your IT security budget: How to get more bang for the buck
Using key risk indicators to sell your information security program
IT security spending a bright spot in '09, with more growth predicted

Business software for the midmarket
How to create and measure success of a SharePoint governance program
Involving users in business intelligence strategy key for success
Successful SOA means a long process made of small projects
Key IT software solutions: Making smart choices in tough times
Business intelligence vendor comparison: Gartner analyzes the big four
SaaS project costs in detail: The payoff isn't always in cash
CIOs share SaaS contract advice on pricing, customization and more
How to build an effective corporate performance management strategy
SharePoint alternatives seek to fill in the gaps
Packaged social network platforms help manage, grow online communities

Email and messaging for the midmarket
Midmarket data center management guides: Tips and best practices
CIO's cost-cutting measures include move to Gmail
Midmarket firm harnesses email communication as part of disaster plan
Arts center's network infrastructure hits right note with Wi-Fi, FMC
When Microsoft shuts you down and other IT horror stories
CIOs, unified communications and the lost art of conversation
Fixed-mobile convergence saves firms costly mobile phone charges
CIOs grapple with tying Wi-Fi, VoIP into unified communications plan
Unified communications: Savvy business move or security meltdown?
Unified communications security: How safe is it?

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Mid-market CIO Business Solutions on Data Integrity, Unified Communications, and Virtualization
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2007 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts