Index arrow Internet Business arrow Email Marketing

GLBA: Raising Email Security Awareness PDF Print E-mail
Written by Administrator   
Corporations are under the gun to protect financial information
and consumers are watching!

Just a few weeks ago, one of the world’s largest banks announced that it had lost computer data containing the personal information of an estimated 1.2 million federal employees, including some members of the U.S. Senate. The missing information includes Social Security numbers and account data for government employees who use the bank’s charge cards for travel and expenses. In the aftermath of these revelations, the ability of banks and other financial institutions to safeguard our personal information has been called into question by consumers and government alike. Predictably, we are beginning to hear the rumblings of additional legislation, but there have been laws protecting consumer financial information on the books for years – laws such as the Gramm-Leach-Bliley Act (GLBA).

The effect of this legislation and consumer awareness hits squarely on the issue of email security. Customers receive their bank statements via email; bank officers pass countless sensitive email messages back and forth to one another; financial spreadsheets are included in email communication on a regular basis. This reliance on email is bringing information privacy and security into the spotlight.

With international attention now focused on privacy and information security, executives are scrambling to ensure that their enterprises are not only compliant with the law, but that they also convey a sense of security to consumers who ultimately vote with their pocketbooks. As an email security company, our interest is in understanding how these issues affect an organization’s email system.

The Gramm-Leach-Bliley Act was signed by former President Clinton in 1999 and made fully effective on July 1, 2001. GLBA requires financial institutions (including banks, brokerage firms, insurance companies and tax preparation firms), as well as all of their business partners and contractors, to protect the private financial information that passes through their enterprises.

GLBA Requirements
GLBA requires financial institutions and their partners to make various information security best practices part of everyday operations. This includes:




Ensuring that email messages containing confidential information are kept secure when transmitted over an unprotected link

Ensuring that email systems and users are properly authenticated so that confidential information does not get into the wrong hands

Protecting email servers and network drives where confidential information may be stored


Even without government regulations defining acceptable communication behavior, financial institutions are faced with the need to protect confidential data and keep their networks operational and secure. The consequences of a failure to perform in any of these areas could have devastating effects on the business itself – potentially causing existing and potential customers to lose faith in the company’s ability to protect their identities and financial information. If that doesn’t strike fear into your heart, GLBA provides for imprisonment of company officers and steep monetary fines for non-compliance.

Components of GLBA Compliance
There are five general sections of the “safeguards” rule contained in GLBA. They outline, at a very high level, what to implement to meet these requirements – not how to implement them. In fact, nowhere does the safeguards rule mention specific technologies or products such as firewalls, encryption, and content filtering that must be in place in order to contribute to compliance. However, the use of each of these technologies is necessary in order to properly secure the email gateway against compliance violations. On the same note, experience and time have shown that technology alone is not an information security catch-all.

An effective information security program also needs specific policies and procedures in place to assist with managing information risks on an ongoing basis. Once these policies and procedures have been defined, the technology should provide automated implementation, enablement and enforcement of them.

Obviously, no single email security component can be used to secure all information; a solid information security infrastructure must consist of a combination of several technologies:



Firewalls and intrusion prevention systems accept or deny traffic into and out of networks.

Encryption ensures data integrity and confidentiality during transport across the Internet.

Content filtering monitors the conversations traveling into and out of the network, scanning for terms that could indicate a violation of regulatory or corporate policy.

Attachment filtering provides inspection of files sent within email messages to ensure that no confidential data is transmitted without proper safeguards in place.


The need to establish centralized policy-based governance over the transmission, encryption, and archival of sensitive information requires a secure gateway-based solution. The solution should be capable of interfacing with all of an organization’s business partners regardless of the partner’s technological capabilities, and it should be transparent to the user in order to maximize the efficiency and utility of email and encourage adoption of acceptable means of corporate communication.

IronMail: The Compliance Appliance
The award-winning IronMail email security appliance from CipherTrust is widely recognized as the benchmark by which all others are measured. IronMail’s Compliance Control allows organizations to set customize policies to easily and automatically manage non-compliant messages as soon as they are detected. Because Compliance Control is policy-driven, most functions are automated, with exceptions handled directly by a decision-maker such as the compliance officer, rather than by an intermediary such as a network administrator interpreting rules made by another party. In addition, powerful reporting and monitoring tools give executives and administrators access to real-time information pertaining to non-compliant email messages.

To learn more about IronMail’s Compliance Control and how it can help your organization comply with the stringent GLBA legislation, download CipherTrust’s free whitepaper, "IronMail Compliance Control: Contributing to Corporate Regulatory Compliance".

Author:
CipherTrust is the leader in anti-spam and email security. Learn more by downloading our free whitepaper, “Contributing to Sarbanes-Oxley Compliance with IronMail” or by visiting www.ciphertrust.com.

 


51.jpg

116.jpg

26.jpg

94.jpg

Index arrow Internet Business arrow Email Marketing

Results 41 - 50 of 215


Is RSS Here to Stay or Gone Tomorrow? Author : Administrator
RSS is totally hot. We have seen it everywhere, from John-Doe blogsites to major news websites. If you haven't heard of RSS before, that's okay, because I hadn't either until a couple of months ago! RSS stands for Really Simple Syndication, or whatever you want it to stand for. I have seen it also stand for RDF Site Summary, but it really doesn't matter. What's important is what it does. Here's how RSS works: Every site that has constant...

Unleash The Power Of Email Marketing Author : Administrator
A direct mail campaign can cost you a lot of money. Contacting people via phone or voice mail can be very time-consuming and frustrating. Given the inherent problems with these traditional marketing techniques, it`s important to master the basic strategies for incorporating email into your overall campaign. As I`ve just shown you, sending out an email can be much cheaper and less of a hassle than other marketing methods. Proceed with caution, ...

Access Your PC From The Road Author : Administrator
Have you ever sat in front of your computer and wished you could show someone else what appeared on your screen? Maybe you were experiencing a problem, or couldn't figure out how to make something work, but you knew if someone else could see what was happening on your screen, they could help you fix the problem immediately. Ever had a phone conversation with someone about a particular business topic, but you just couldn't "connect" ...

Demand for Spam? It exists Author : Administrator
Do you like spam? No, I'm not kidding. Everybody knows what spam is, almost everybody seems to have learned by heart simple advice like "do not click ..." "do not respond..." , "do not buy..." but On March 23, 2005 Mirapoint and the Radicati Group, a consulting and market research firm, released preliminary results of their end-user survey on email hygiene. "This preliminary data is surprising and somewhat shocking to us," said Marcel Nienhuis,...

Grab Those Emails! – 11 Key Ways to Get Your Visitors to Hand Over Their Email Addresses Author : Administrator
If you are trying to get an opt-in email list going for you website, you might be wondering where to start. The most important rule to understand is that you must persuade your website visitors to let you have their, oftentimes guarded and protected, email addresses. Remember, a lot of people surfing the web these days are pretty internet savvy. They are aware of spam, hate spam and do not want spam in their inbox… ever. If they do not feel th...

Sending anonymous email Author : Administrator
Whatever you do with the following information is solely your responsibility. #telnet ip:25 That title looks like random letters and symbols, but it is actually the command used to connect to an SMTP server via telnet. The # represents the shell, “telnet” is the program used to start a connection via telnet, “ip” is the ip address of the mail/smtp server (an SMTP server comes with XP PRO and is easy to set up), and 25 is the port SMTP daemons r...

5 Rules of Forwarding E-mails Author : Administrator
Forwarding of e-mails is one of the topics I get contacted about the most. And, one which also causes hurt feelings and misunderstandings more than any other topic. Daily, e-mails flow in from onliners asking about a "nice way" of telling someone they care about, relative, friend or associate to not forward attachments, chain e-mails, political commentary or the jokes that are so prevalent online. Netizens are afraid to ask others to stop and ...

GLBA: Raising Email Security Awareness Author : Administrator
Corporations are under the gun to protect financial information and consumers are watching! Just a few weeks ago, one of the world’s largest banks announced that it had lost computer data containing the personal information of an estimated 1.2 million federal employees, including some members of the U.S. Senate. The missing information includes Social Security numbers and account data for government employees who use the bank’s charge cards ...

Alert: New HIPAA Rules Could Affect Your Organization Author : Administrator
Failure to adhere to the new guidelines could cost your company up to $250,000 per infraction! On April 21, 2005 (just over three weeks from today), a new Health Insurance Portability and Accountability Act (HIPAA) security rule goes into effect. The requirements of this rule, which are basically information security best practices, focus on the three cornerstones of a solid information security infrastructure: confidentiality, integrity and...

Sarbanes-Oxley: A Cross-Industry Email Compliance Challenge Author : Administrator
Is your enterprise following the rules? The bulk of financial information in many companies is created, stored and transmitted electronically, maintained by IT and controlled via information integrity procedures and practices. For these reasons, compliance with federal requirements such as the Sarbanes-Oxley Act (SOX) is heavily dependent on IT. Companies that must comply with SOX are U.S. public companies, foreign filers in U.S. markets and p...

  
Top
 
 
 
© 2008 mmakers.org
Joomla! is Free Software released under the GNU/GPL License.