Problem solve Get help with specific problems with your technologies, process and projects.

Preventing unauthorized email issues from hindering an organization

In this expert response, find out how to prevent your organization from sending out unauthorized emails.

A recent prediction from Symantec Corp. said, "As the economy continues to suffer and more people seek to take advantage of the loose restrictions of the CAN-SPAM Act, we'll see more organizations selling unauthorized email address lists and more less-than-legitimate marketers spamming those lists." Under what circumstances could your organization do this legitimately, and what can you do to make sure this doesn't happen?
This question is as much about ethics as it is about the information security threats posed by sending out legitimate commercial emails. Commercial, unauthorized email has its place on the Internet, but you must protect your organization from crossing the line and becoming a spammer.

Organizations can buy a legitimate commercial email list in several ways. Infosec pros should develop relationships with marketing departments, and integrate themselves into their projects. This doesn't mean constant communication about all of the details, but if there is a question of technology use, the IT department should take action to ensure the information security risk is minimized for the organization. This could mean explaining to the marketing department that using the list they bought on the black market could have negative repercussions, such as reputation loss or being put on spammer blacklists. Companies can also buy or rent a list through legal means, or get access to addresses by sponsoring an event like a seminar or conference and making it clear the participants' contact information is going to be used for marketing purposes related to the event.

Make sure the marketing department is only purchasing lists from legitimate businesses, and scrutinize the terms and conditions under which the email addresses were collected. Then, be sure to honor the original terms and conditions when sending commercial email to the list.

This was last published in May 2010

Dig Deeper on Email and Messaging Threats-Information Security Threats

Have a question for an expert?

Please add a title for your question

Get answers from a TechTarget expert on whatever's puzzling you.

You will be able to add details on the next page.

Start the conversation

Send me notifications when other members comment.

Please create a username to comment.