IM security best practices for SMBs

IM security best practices for SMBs

Joel Dubin, CISSP, Contributor
Instant messaging (IM) can be beneficial internally and externally for small and medium-sized businesses (SMBs). It's also affordable and easy to deploy.

More on IM
Unified messaging comes of age for SMBs

IM and blogs next target for litigation
But that external connectivity, if not configured securely, can come with a heavy price. IM allows viruses,

    Requires Free Membership to View

    Download Enterprise CIO Decisions for free after registering.

    After registering we will email you the latest issue as well as access to our archive of back issues. Get essential editorial insights that senior IT executives need to run IT operations effectively and efficiently.

    Get Enterprise CIO Decisions Now!

    By submitting your registration information to SearchCIO-MidMarket.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchCIO-MidMarket.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

Trojans and other malware to piggyback into your networks far easier than email attachments. IM messages can contain links to malicious Web sites, and confidential data can be compromised. Spam over IM (SPIM) is also a threat.

Thus, security for IM is essential. Here are some suggestions and best practices for securing IM without breaking the bank:

  • Designate one IM tool. For internal IM, make sure to use a single enterprise software application. More vendors are offering IM products for SMBs, such as IBM's Lotus Sametime. It installs on its own dedicated server, which is tucked deep inside your company's firewall. Harden that server as you would any other: limit access to authorized users, turn off unnecessary services, install antivirus software and keep patches up to date. Install the client piece of the product only on desktops that have been equally hardened with up-to-date antiviral protection and host-based firewalls.
  • Restrict external IM usage. Allow usage only for employees who have to communicate real time. Don't use consumer IM products from America Online, Yahoo Inc. or Microsoft. Use enterprise instant messaging (EIM) software such as Jabber or Akonix.
  • Make sure your EIM provider offers some kind of encryption. You can always encrypt with Secure Sockets Layer at no extra cost. Remember, IM messages are conventional HTTP traffic, whether the messages go over port 80 or not.
  • Restrict access. Like your internal IM servers, those hosting your EIM should be locked down with restricted access, hardening and updated patches and antiviral protection. They should be hidden behind your company's firewalls, but unlike your internal IM servers, they will need access to the Internet. Make sure to add rules to your firewall allowing access only to your EIM and blocking common ports for consumer IM products.
  • Restrict communication. Configure buddy lists on your EIM to restrict communication to only known and trusted parties. This will prevent a malicious user from trying to access your network via IM.
  • Log and monitor all IM traffic. This can be used to detect malicious inbound traffic, or inappropriate outbound traffic, like someone trying to send out confidential company data or files.

Joel Dubin, CISSP, is an independent computer security consultant. He is a Microsoft MVP specializing in Web and application security, and is the author of The Little Black Book of Computer Security, available from Amazon.com. He also runs The IT Security Guy blog at http://www.theitsecurityguy.com.

This was first published in May 2007

Join the conversationComment

Share
Comments

    Results

    Contribute to the conversation

    All fields are required. Comments will appear at the bottom of the article.

    Disclaimer: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.