Randy George

Tags: , , , ,

Channel: Security, Data Center, Data Protection

See more from this blogger

E-Mail Encryption Goes Mainstream

Fess up, have you ever emailed your credit card number or Social Security number to a friend, family member, or even to a third party? I have, and yes, I was a bonehead for doing it. In the business world, you need to make sure your employees aren't doing it either. Why should you care? New state mandated data privacy regulations are changing the rules of the game when it comes to emailing Personally Identifiable Information (PII) in cyberspace. Simply stated, it's bad business, and it's becoming increasingly illegal.

If you work in Massachusetts, as I do, then you've probably been tied down for months strategizing on how you'll deal with the new state mandated Data Privacy Law. I'm not a lawyer, but I play one at work, so here's an attempt to summarize pages of Latin and legal jargon in a few sentences. Regardless of where you do business, if you collect or distribute the PII of a Massachusetts resident during the course of business, you are subject to the new MA Data Privacy Law. If you mishandle the PII of a Massachusetts resident through carelessness, you are subject to a maximum penalty of $5,000 per customer record lost.

Let's put that into perspective. Suppose that as a travel agent, you store the credit card info for your top 100 business customers for their billing convenience. Let's further suppose that the laptop on which you stored those credit card numbers fell into the wrong hands or was lost. Theoretically, you're exposed to possible fines of $500k. That's a crippling fine for a boutique travel agency, assuming that liability insurance doesn't cover you.Now let's assume you're a university, and you lose the PII of 25,000 students. See where we're going?  The potential penalties, and negative PR, amount to huge dollars lost.

The key takeaway is that strict data privacy legislation is coming to your state, if it hasn't arrived already. If you don't have any encryption capabilities in the datacenter now, start with what is probably the biggest threat vector for every organization: E-mail. If you have a data loss prevention (DLP) appliance, then you probably already know how common it is for PII to be emailed out to the world unencrypted. You might catch your HR department forwarding employee socials to benefit providers via unencrypted email. You might learn that the sales team has been taking credit card orders via e-mail from customers instead of using the secure channels. The amount of possible business processes that are broken, and that expose you to risk, are likely more numerous than you know.   

The technology solution? Consider shooting all of your outbound email through an easy-to-manage email encryption appliance, like McAfee's Secure Mail Gateway or Cisco's Ironport appliance. Let the built in appliance PII dictionaries make the decision as far as what to encrypt. Managing email encryption appliances are generally a pretty easy task, and for the cost, it gives your compliance initiative great bang for the buck.
 

Related Reading


More Insights




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

Network Computing encourages readers to engage in spirited, healthy debate, including taking us to task. However, Network Computing moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. Network Computing further reserves the right to disable the profile of any commenter participating in said activities.

 
Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
 

Research and Reports

Storage Virtualization Guide
May 2012

Network Computing: May 2012

TechWeb Careers