Home > Security Tips > Compliance Counselor > Strategies for email archiving and meeting compliance regulations
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

COMPLIANCE COUNSELOR

Strategies for email archiving and meeting compliance regulations


Michael Cobb, Contributor
02.18.2009
Rating: -3.20- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


A study released in late 2008 by Barracuda Networks Inc. looked at email messaging archive technology adoption among North American organizations. An overwhelming majority, nearly 82%, of the surveyed 200 IT professionals viewed email archiving, commonly defined as an approach to saving and protecting email data for future use, as "important" or "very important" for their organizations. Interestingly, more than two-thirds of respondents cited reasons other than compliance as their main consideration for implementing an email archiving product.

I find it encouraging that regulatory requirements are not the only forces driving good IT practices. For 29% of organizations, however, compliance with industry regulations was the critical factor behind archiving email. So which regulations make archiving an increasingly important element of network administration and compliance? In this tip, we'll touch on some regulations driving email archiving, why archiving is important, and how to avoid common mistakes made when dealing with archived data.

Compliance regulations driving email archiving
To start, there are two regulations that affect the majority of organizations. To address electronically stored information, amendments to the aging Federal Rules of Civil Procedure (FRCP) require organizations to manage their data so that it can be produced in a timely and complete fashion when required in the course of legal proceedings.

More on email archiving

A SearchSecurity.com reader recently asked our security management expert, "Does SOX provision email archiving?"

In our Messaging Security School, learn about email security tools, systems and threats.
This change to the FRCP, which basically applies to every business in the United States, means that some form of archiving product is invaluable for timely email discovery. In the Barracuda survey, nearly half of the respondents said they had been involved in a litigation request that required email as part of the discovery process. A third of them even took up to a month, without the aid of an email archiving product, to produce email as part of an e-discovery request.

Publicly traded companies must also comply with the Sarbanes-Oxley Act of 2002, which stipulates that electronic data must be kept for 3-7 years. Given that the number of email messages for large organizations can run into millions each year, standard backup approaches, such as tapes used for disaster recovery, are not going to provide effective retrieval capabilities. On the other hand, a dedicated email archive can take advantage of indexing, tagging, custom searches and efficient storage to make message retrieval less painful.

Additionally, though it only affects healthcare and insurance providers, the Health Insurance Portability and Accountability Act (HIPAA) requires personally identifiable information to be encrypted both at rest and in transit. A product dedicated to archiving email can handle this requirement as well.

There are also various rules, imposed by bodies such as the Securities and Exchange Commission, the National Association of Securities Dealers, and the New York Stock Exchange, that cover the handling and storage of electronic messages. Although these are mainly touch firms in the financial services industries, they add to the weight of regulation, which requires electronic messages to be stored and secured against alteration, deletion and inappropriate access, yet easily retrievable when required.

Don't miss need-to-know info!

Security pros can't afford to be the last to know. Sign up for email updates from SearchSecurity.com and you'll never be behind the curve!
The case for email archiving
For organizations of any size, there is a compelling argument for implementing some form of specialized email archiving. Not only will it make compliance easier and less time consuming, but it also leads to a more efficient network and user base. Without some form of email archiving, an email inbox can get quite large, with tens of thousands of emails. If, in order to abide by compliance regulations, users aren't allowed to delete any of them because they are not being archived, mailboxes with that many messages can quickly become unmanageable, both for users and administrators. Even Microsoft recommends large enterprise users of Exchange move old emails out of email boxes to a third-party email archiving product to improve user productivity.

The key aspects to choosing the right product are to ensure it will integrate with existing infrastructure, and that it has the functionality to help meet the organization's unique regulatory obligations. For instance, an effective email archiving system should provide a warning when unauthorized attempts are made to access the archive, or when emails violate acceptable content policies.

Also note that it is essential that the organization store emails in a format that does not change the information. Encryption is allowed and obviously recommended, but any form of compression, such as stubbing, which is the process where only one copy of an email attachment is kept and all other copies act as pointers to the individual one, must not remove or lose information about points of origin, destinations, dates and times.

There are many email archiving products available, many of which are designed to enable compliance with specific regulations. Taking time to review the available product options will help ensure your organization finds the correct balance between performance and productivity -- making sure the system runs smoothly without interrupting business activities -- and meeting security and compliance requirements.

About the author:
Michael Cobb, CISSP-ISSAP is the founder and managing director of Cobweb Applications Ltd., a consultancy that offers IT training and support in data security and analysis. He co-authored the book IIS Security and has written numerous technical articles for leading IT publications. Mike is the guest instructor for several SearchSecurity.com Security Schools and, as a SearchSecurity.com site expert, answers user questions on application security and platform security.


Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




BROWSE BY TAG
Compliance Counselor,   Security Audit, Compliance and Standards,   IT Security Audits,   Application and Platform Security,   Email Security Guidelines, Encryption and Appliances,   Email Protection,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Compliance Counselor
The future of PCI DSS encryption requirements? Tokenization for PCI
Security compliance predictions for 2010: New regulations, new technology
Compliance strategy: How to become an internal IT auditor
GRC customers point to better efficiency, convergence and consistency
Benefits of ISO 27001 and ISO 27002 certification for your enterprise
Identity lifecycle management for security and compliance
Interpreting 'risk' in the Massachusetts data protection law
FTC Red Flags Rules: How to create an identity theft prevention plan
Creating a HIPAA employee training program
Data protection tips for corporate compliance leaders

IT Security Audits
Compliance strategy: How to become an internal IT auditor
A guide to internal and external network security auditing
Standards compliance does not equal sound information security risk management
Tony Spinelli: Prioritize Information Security over Compliance
How to prepare for a FERPA audit
MasterCard increases PCI compliance requirements for some merchants
How to select a set of network security audit guidelines
How to write a risk methodology that blends business, security needs
PCI compliance requirement 11: Testing
Using IAM tools to improve compliance

Email Security Guidelines, Encryption and Appliances
Information security book excerpts and reviews
How to confirm the receipt of an email with security protocols
Best Email Security Products
Can an IP spoofing tool be used to spam SPF servers?
WatchGuard acquires email and Web security vendor BorderWare
McAfee to acquire email SaaS vendor MX Logic
What does 'invoked by uid 78' mean?
How to configure firewall ports for webmail system implementation
Fierce competition prompted new Cisco email security options
Cisco brings email security appliances closer to SaaS

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
asymmetric cryptography  (SearchSecurity.com)
challenge-response system  (SearchSecurity.com)
cryptographic checksum  (SearchSecurity.com)
data encryption/decryption IC  (SearchSecurity.com)
elliptical curve cryptography  (SearchSecurity.com)
Escrowed Encryption Standard  (SearchSecurity.com)
MPPE  (SearchSecurity.com)
Quiz: Cryptography  (SearchSecurity.com)
session key  (SearchSecurity.com)
Twofish  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Research Solutions for Network Security, Access Control and Security Threats
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2010, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts