Wednesday, August 3, 2011

Email security problem

Due to the volume of spam messages being sent through email servers each day, email administrators are sometimes faced with the important choice of whether to deliver identified spam to a quarantine mailbox, or alternatively just delete them. Now, because email is considered to be a 'best effort' services, and while much of the time that 'best effort' is very good, there will always be technical or security reasons that may prevent a message from reaching it's destination. Despite this, most end users perceive email as a reliable form of communication on par with the telephone, so it would be considered unacceptable for a crucial message to be prevented from reaching the recipient it was intended for due to being trapped in a spam filter or worse, just deleted.

So when developing your email security plan, you'll want to decide early on what is to be considered spam. Once you've have clearly identified the elements your filtering system are looking for, you must then decide what to do with spam when it has been identified. There are several things to consider before deciding on your spam filtering protocol.

Admin Overheads

For some businesses a quarantine folder appears to be the only option (which it may be for some businesses with strict email security and regulation) but the costs of administration managing a quarantine system can become costly both in time and money. A staff member will need to regularly review the folder to release any false positives and emptying it of any actual spam messages. If it iss not possible for the organisation to devote an individual to this task, they may find this results in IT being inundated with requests from staff to locate and release emails that fail to arrive, even if the spam filter is not the reason for a email not arriving. An alternative to this would be to bypass the user's inbox and send any flagged messages directly to their junk mail folder, which clear messages after a specified amount of time, but which will allow users to locate missing messages allowing IT to focus on other business critical issues.

Space

When a business chooses to use quarantine as part of their email security system, the amount of email data being sorted can grow quite rapidly. Research has estimated that over 50% of email is in-fact spam, with less conservative estimates saying as high as 80%. All of this spam needs to kept somewhere which can start to add up to a lot of space and could cause a business to rethink its email retention policy or may even result in them considering skipping quarantine and simply deleting messages.

Time Critical Messages

The major issue with deleting spam is the possibility that a time sensitive piece of information could be incorrectly identified as spam, and thus be deleted before ever reaching the recipients inbox - information like a contract or quote for an important project could just disappear. So before deleting all flagged messages, it's crucial to make sure your company comprehends the consequences of doing so, to ensure that critical data isn't lost. One way to safe guard against loosing important emails because of spam filters is to create white-lists for vendors, business partners and clients, that way the chance of messages from these avenues don't run the risk of being destroyed.

Message Delay

Finally, there is the issue of delays. Because a quarantined message must first be reviewed before being released, this means that emails reliability and speed are compromised. So even if the quarantine folder is reviewed twice a day by a staff member, messages can be left waiting for review for hours or even over night. As for deleting spam, a missing message may go unnoticed until a client phones asking why they have not received a response.

As an email administrator, you will want to document as well as communicate to your users your email security system. This should include letting users know what your policy is as well as the email teams responsibilities regarding spam retention and deletion - to ensure that business critical messages get to your users without issue.

Search Tags


free email protection
email protection agency
email content security
email encryption solution
postini email encryption
barracuda email security service
business email security
email security solutions
email encryption solutions
email safety rules
secure email portal
tls email encryption
email encryption software reviews
hipaa email encryption
email security threats
email encryption appliance
barracuda email encryption
hosted email encryption
web based email security
secure email gateway
email file encryption
email encryption services
most secure email provider
email security tips

No comments:

Post a Comment