Home > E-mail policies -- A defense against phishing attacks
Book Chapter:
EMAIL THIS LICENSING & REPRINTS

E-mail policies -- A defense against phishing attacks

12 May 2005 | John Wiley & Sons

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

Phishing: Cutting the Identity Theft Line
By Rachael Lininger and Russell Dean Vines                          334 pages; $29.99                     John Wiley & Sons
In this excerpt of Chapter 6 from Phishing: Cutting the Identity Theft Line, authors Rachael Lininger and Russell Dean Vines explain how e-mail policies help protect companies from phishing attacks.


Interacting with customers

Not surprisingly, the first line of defense in the phish fight is the customer. Creating easily understandable standards for customer communications can go a long way in preventing a phishing attack and recovering quickly from one.

E-mail

E-mail is currently the largest attack vector for phishing malware and ID theft exploits. This may change, as Web sites increasingly begin to employ advanced scripting techniques and automated functions; but e-mail is still the hands down winner.

You can take a number of steps to protect your business from fraudulent e-mail, including the following:

  • Standardizing your communications with the customer
  • Implementing e-mail authentication
The following sections discuss these topics in more detail.

Information Security Bookshelf

Read Chapter 6, Helping Your Organization Avoid Phishing

Sound Off on this book excerpt

More book chapters and reviews

Learn more about e-mail security in E-mail Security School

Standard customer communication policy

Even if you're not a financial institution, as an ISP or Internet company you should have a customer e-mail policy. Policy is one of those terms that can mean several things. For example, there are security policies on firewalls, which refer to the access control and routing list information. Standards, procedures and guidelines are also referred to as policies in the larger sense of a global information security policy. For example, a policy can provide protection from liability due to an employee's actions, or it can control access to trade secrets.

Companies need many types of policies, standards, guidelines and procedures. But what I'm talking about here is creating a standard for e-mails from the company to the customer, which doesn't use the types of phish hooks you see in a phishing e-mail. A standard customer communications policy should convey a consistent message and not confuse your customer.

Here are some basic customer e-mail policy standards:

  • Don't send e-mail in HTML format.
  • Don't send attachments.
  • Don't include or ask for personal information.
  • Use the full name of the user.
  • Don't include hyperlinks.
  • Use localized messages.

Read Chapter 6, Helping Your Organization Avoid Phishing.

Sound Off! -   Post your comments |  See others' comments (1)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Phishing
Trojan downloaders, droppers skyrocket, Microsoft says
New phishing, Zeus Trojan technique spreads crimeware
New Storm attack exploits April Fool's Day
Clinton, Obama campaigns used in spam blasts
How secure is online banking today?
Google-Postini email services deliver security market message
PDF spam reemerges in some inboxes
Researcher warns of new do-it-yourself phishing program
Spam continues surge as spammers become clever in '07
How effective are phishing links that refer to FTP sites?
Phishing Research

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
crimeware  (SearchSecurity.com)
pharming  (SearchSecurity.com)
phishing  (SearchSecurity.com)
Rock Phish  (SearchSecurity.com)
spear phishing  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineWebcastsWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts