Upcoming Events

Interop NY
Oct. 1-5

Interop is the only event to give you a comprehensive and unbiased understanding of all the latest innovations-including cloud computing, virtualization, security, mobility and data center advances-that help position your company for growth.

Register Now!

More Events »

Subscribe to Newsletter

  • Keep up with all of the latest news and analysis on the fast-moving IT industry with Network Computing newsletters.
Sign Up

Strategic Security: The Encryption Conundrum

Tags: , , , , , , , , , , , , , , , , , , , , , , , , , , , ,

Channel: Other, Networking & Mgmt, Data Protection, E-discovery, UC & VoIP

Companies deploying end-to-end e-mail encryption often do so to meet state and federal regulations. Ironically, the encryption architecture may stymie administrators charged with enforcing security and policy compliance, which may lead to other legal risks.

As described in "Bolt Down Your E-Mail", an end-to-end e-mail encryption architecture places the encryption keys and functionality on the user's PC. This strategy may suit an organization with only a few users who deal with sensitive information. But the benefits of end-to-end encryption may be overshadowed by the risks associated with being unable to monitor these communications.

For instance, a user could employ the encryption system to facilitate the theft or transfer of trade secrets or other confidential information. End-to-end encryption also defeats content filtering and data leak-prevention systems designed to meet regulatory requirements.

A lesser known concern is an emerging legal standard regarding failure to enforce a monitoring policy--an obvious result if you can't read encrypted messages--which may lead to serious disadvantages in civil litigation.

Under certain circumstances, your company may be prohibited by a court from retrieving, for litigation purposes, the messages sent or received by a former employee in which she discussed legal matters concerning your company with her attorney. The "work product" doctrine and the attorney-client privilege (legal rules designed to protect the confidentiality of attorneys' files and their client communications, respectively), may kick in if you fail to enforce the "personal-use ban"--the common corporate policy restricting computer use to work purposes.


Page:  1 | 2 |Next Page »

Related Reading


More Insights




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

Network Computing encourages readers to engage in spirited, healthy debate, including taking us to task. However, Network Computing moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. Network Computing further reserves the right to disable the profile of any commenter participating in said activities.

 
Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
 

Research and Reports

Storage Virtualization Guide
May 2012

Network Computing: May 2012

TechWeb Careers