![]() |
Search |
Submit ArticleIf you would like to submit an article, click the button below. Navigation |
GLBABy: CipherTrust, Sat Dec 10th, 2005 12:41:39 AM b>Corporations are under the gun to protect financial information and consumers are watching! Just a few weeks ago, one of the world’s largest banks announced that it had lost computer data containing the personal information of an estimated 1.2 million federal employees, including some members of the U.S. Senate. The missing information includes Social Security numbers and account data for government employees who use the bank’s charge cards for travel and expenses. In the aftermath of these revelations, the ability of banks and other financial institutions to safeguard our personal information has been called into question by consumers and government alike. Predictably, we are beginning to hear the rumblings of additional legislation, but there have been laws protecting consumer financial information on the books for years – laws such as the Gramm-Leach-Bliley Act (GLBA). The effect of this legislation and consumer awareness hits squarely on the issue of email security. Customers receive their bank statements via email; bank officers pass countless sensitive email messages back and forth to one another; financial spreadsheets are included in email communication on a regular basis. This reliance on email is bringing information privacy and security into the spotlight. (Article continued below)
With international attention now focused on privacy and information security, executives are scrambling to ensure that their enterprises are not only compliant with the law, but that they also convey a sense of security to consumers who ultimately vote with their pocketbooks. As an email security company, our interest is in understanding how these issues affect an organization’s email system. The Gramm-Leach-Bliley Act was signed by former President Clinton in 1999 and made fully effective on July 1, 2001. GLBA requires financial institutions (including banks, brokerage firms, insurance companies and tax preparation firms), as well as all of their business partners and contractors, to protect the private financial information that passes through their enterprises. GLBA Requirements GLBA requires financial institutions and their partners to make various information security best practices part of everyday operations. This includes:
Components of GLBA Compliance There are five general sections of the “safeguards” rule contained in GLBA. They outline, at a very high level, what to implement to meet these requirements – not how to implement them. In fact, nowhere does the safeguards rule mention specific technologies or products such as firewalls, encryption, and content filtering that must be in place in order to contribute to compliance. However, the use of each of these technologies is necessary in order to properly secure the email gateway against compliance violations. On the same note, experience and time have shown that technology alone is not an information security catch-all. An effective information security program also needs specific policies and procedures in place to assist with managing information risks on an ongoing basis. Once these policies and procedures have been defined, the technology should provide automated implementation, enablement and enforcement of them. Obviously, no single email security component can be used to secure all information; a solid information security infrastructure must consist of a combination of several technologies:
IronMail: The Compliance Appliance The award-winning IronMail email security appliance from CipherTrust is widely recognized as the benchmark by which all others are measured. IronMail’s Compliance Control allows organizations to set customize policies to easily and automatically manage non-compliant messages as soon as they are detected. Because Compliance Control is policy-driven, most functions are automated, with exceptions handled directly by a decision-maker such as the compliance officer, rather than by an intermediary such as a network administrator interpreting rules made by another party. In addition, powerful reporting and monitoring tools give executives and administrators access to real-time information pertaining to non-compliant email messages. To learn more about IronMail’s Compliance Control and how it can help your organization comply with the stringent GLBA legislation, download CipherTrust’s free whitepaper, "IronMail Compliance Control: Contributing to Corporate Regulatory Compliance". About the author: CipherTrust is the leader in anti-spam and email security. Learn more by downloading our free whitepaper, “IronMail Compliance Control: Contributing to Corporate Regulatory Compliance” or by visiting www.ciphertrust.com. |
Sign In |
|
Home |
Contact Us |
XML SiteMap Free Articles © 2004 - 2008 - Information Articles | ||