Home > Financial Services Information Security Tips > Security Architecture Insider > Secure instant messaging in the enterprise
Financial Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

SECURITY ARCHITECTURE INSIDER

Secure instant messaging in the enterprise


Mike Chapple
07.19.2006
Rating: --- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


Instant messaging (IM) platforms, such as AIM, Yahoo! Messenger and Google Talk, have moved beyond the world of high school chatter and into the world of corporate communications. Yet, in many cases, security policies and processes haven't caught up to this technology. It's now time to consider how instant messaging is, and should be, used in your organization, and how to protect against IM threats.

Instant messaging policies

The first step is to clearly state your organization's policy on instant messaging. Can users install and use IM software on systems owned by the organization? If you have a strict "no outside software" policy, you may think you're covered, but keep in mind that Windows XP SP2 ships with Windows Messenger installed, creating a policy loophole.

Here's a set of questions you should consider when defining your organization's IM policy:

  • Is IM use permissible on your network?
  • May users run IM software on systems owned by your organization?
  • Does the organization endorse/require a specific IM platform?
  • Is encryption mandatory?
  • Is IM acceptable for corporate use or for personal communications only?
  • Are there restrictions on the sensitivity of data that may be communicated via IM?
  • Is there a requirement to retain records of IM communication for any period of time?

Once you have a clear policy on IM use, educate your users on policy requirements and their responsibilities.

Instant messaging security measures

If you decide to allow instant messaging, blanket it with layers of protection to ensure you're organization is protected against the viruses, worms and other malicious code that's become prevalent on IM networks. Run a modern antivirus program that includes IM scanning on all workstations, and consider a using network-based content filter that scan...


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Security Architecture Insider
Security benefits of virtual desktop infrastructures
How to secure data backup
Too many encryption methods make secure communications difficult
How to streamline role-based access control
Five considerations for choosing network access control products
Fighting fraud: Understanding technology and threats
How to shift to centralized authentication and ease compliance
Winning the war: Personal information protection
Why financials must implement Web application security best practices
Identity management for financial firms in turbulent times

Enterprise email security and messaging security
Too many encryption methods make secure communications difficult
Shifting to a flexible information security framework
Google ordered to deactivate Gmail account after bank email error
Wyoming bank sues Google after bank employee email mishap
Wells Fargo deploys Voltage for secure email
Study of banking malware analyzes underground economy
Cisco: Cybercriminals more savvy than ever in 2008
Secure communications
How to easily integrate managed email security services
Email security and compliance best practices, part two

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


s IM traffic for malware.

You also want to prevent the threat of eavesdropping on your traffic as it traverses public networks. Out of the box, IM software uses public servers hosted by the IM provider, which means all messaging must traverse the public Internet on its way to and from the server. If you think your users might send sensitive messages through IM (accidentally or intentionally), you should strongly consider encrypting that traffic. Unfortunately, encrypted IM is a relatively immature technology that typically requires a specialized client. One standout in this field is the free Trillian client by Cerulean Studios, which supports multiple IM networks and allows encrypted communications with other Trillian users.

The ultimate option in secure instant messaging is to run your own managed IM server or gateway. This eliminates the threat of outsiders intercepting internal messages as they cross the Internet by keeping the traffic on the local network, and it's actually easier than you might think. Many of these products allow you fine-grained control over the types and destinations of IM traffic on your network. In addition to the commercial products available, you may wish to consider the open-source Jabber IM server project.

Instant messaging is here for the foreseeable future and poses a significant challenge to information security professionals. If you're not able to block IM completely due to business requirements, you should certainly consider implementing strong controls to limit the risk this technology poses to your organization.

About the author
Mike Chapple, CISSP is an IT Security Professional with the University of Notre Dame. He previously served as an information security researcher with the National Security Agency and the U.S. Air Force. Mike is a frequent contributor to SearchSecurity, a technical editor for Information Security magazine and the author of several information security titles, including the CISSP Prep Guide and Information Security Illuminated.

Rate this Tip
To rate tips, you must be a member of SearchFinancialSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Finance Sector Security - Anti-Phishing, Remote Access Security, Firewall Systems
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2008 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts