Home > Financial Services Information Security Tips > Security Architecture Insider > Ten steps to a holistic secure messaging strategy
Financial Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

SECURITY ARCHITECTURE INSIDER

Ten steps to a holistic secure messaging strategy


Crystal Ferraro, SearchSecurity.com Site Editor
10.28.2003
Rating: --- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


Insecure messaging comes with a host of dangers including data loss, theft and leakage, compromised systems, downtime and loss of productivity. Unfortunately, secure messaging is no longer as straightforward as keeping the latest virus from entering an organization via e-mail. At Information Security Magazine's Security Decisions conference Jim Reavis, president of Reavis Consulting Group, outlined ten steps for a holistic secure messaging strategy. Here are the highlights.

  1. Implement enforceable policies that users understand. Policies should clearly communicate acceptable and appropriate usages with clear definitions and examples. Users should know what is good behavior and what is bad behavior, Reavis said.

  2. Build your messaging architecture to allow for granular rules control. "We need agility in our networks and messaging systems," said Reavis. By compartmentalizing you can improve incident response and provide limited service during an incident.

  3. Develop a formalized computer emergency response team (CERT) and incident response plan specific to messaging incidents. A specialized messaging response team should focus on containment, disinfection, remediation and rebuilding systems.

  4. Create an awareness program to strengthen your last line of defense – your users. Include courseware such as PowerPoints or Flash to reinforce policy and educate about threats and safe practices. Tell users what to do in case of an incident and where to go for help. Make it easy for users to report incidents via the company intranet. If the reporting procedure is difficult or makes users feel dumb, they won't report.

  5. Maintain a baseline and continuous measurement system of your network. "If you don't understand how your network operates, you don't understand your business," Reavis said. This includes network traffic analysis, e-mail and IM logging and trend analysis.

  6. Increase your organization's use of encryption. While encryption is virtually unbreakable, most organizations only encrypt 1% of all messages, Reavis said.

  7. Proxy all connections, including peer-to-peer applications such as instant messaging. You can also do e-mail encryption by proxy, Reavis said. An encryption proxy sits on the network between the e-mail server and the Internet. The proxy manages keys, encrypts messages and gives the recipient the option of a secured SMTP message or Webmail.

  8. Deploy multiple layers of virus/spam protection. There are five possible antivirus scanning points: e-mail client, e-mail server, antivirus gateway, network layer antivirus appliance and a managed security service provider. Reavis recommended using three of these five points and using two different vendors.

  9. Deploy best-of-breed solutions. "This is where the industry is right now. Integrated suites are very immature and don't provide adequate security," Reavis said.

  10. Finally, take an integrated team approach to securing your organization's messaging systems.

For more information on secure messaging, download the presentation Jim Reavis gave at Security Decisions. For more advice from the speakers at Security Decisions, visit this Featured Topic.


Rate this Tip
To rate tips, you must be a member of SearchFinancialSecurity.com.
Register now to start rating these tips. Log in if you are already a member.


Submit a Tip




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Security Architecture Insider
Multifactor authentication options to secure online banking
Security benefits of virtual desktop infrastructures
How to secure data backup
Too many encryption methods make secure communications difficult
How to streamline role-based access control
Five considerations for choosing network access control products
Fighting fraud: Understanding technology and threats
How to shift to centralized authentication and ease compliance
Winning the war: Personal information protection
Why financials must implement Web application security best practices

Enterprise email security and messaging security
Too many encryption methods make secure communications difficult
Shifting to a flexible information security framework
Google ordered to deactivate Gmail account after bank email error
Wyoming bank sues Google after bank employee email mishap
Wells Fargo deploys Voltage for secure email
Study of banking malware analyzes underground economy
Cisco: Cybercriminals more savvy than ever in 2008
Secure communications
How to easily integrate managed email security services
Email security and compliance best practices, part two

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Finance Sector Security - Anti-Phishing, Remote Access Security, Firewall Systems
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2008 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts