Friday | 10 July, 2009
CSO
E-mail and its security discontents
Why Microsoft, Cisco, IBM and others need to step up to protect SMTP
Paul Simmonds (Network World) 16/01/2008 10:10:31

This clear direction, the "You must do this.....," has to be led in a non-partisan way by Microsoft, IBM, HP, Oracle, Cisco, MessageLabs, Postini, Yahoo and Google, and have visible backing of the top-100 global companies that all agree to implement the solution within 12 months and start blocking (or at least discriminating against) e-mail that does not conform.

It is my belief that the Jericho Forum, an international IT security thought-leadership group, and a Managed Consortia of Open Group, a highly-respected vendor and technology neutral consortium, is ideally suited to bring together the best-of-the-best from the vendor community and global companies to play the role of honest-broker to deliver standards on behalf of the global community.

So Bill Gates, you promised an end to spam by 2006; perhaps you would like to champion this as your retirement project?

Ten questions to ask about your e-mail systems:

  1. Do you have a strategy for securing e-mail?
  2. Is your e-mail server capable of SMTP/TLS in at least opportunistic mode?
  3. Can you support a request for forced SMTP/TLS?
  4. Have you updated your DNS to include your SPF records?
  5. Have you trained your people that sending Internet e-mail is like sending a postcard?
  6. Are you alerting your e-mail recipients when an external e-mail is not secure?
  7. Are you feeding SPF and SMTP/TLS attributes into your spam calculations?
  8. When using an (e-mail) marketing company and they spoof your e-mail domain -- do you ensure the SPF is OK?
  9. Do you have processes to ensure content is secured when sending via the Internet?
  10. Does your DNS provider support the latest SPF standard?

Paul Simmonds is a member of the management board of the Jericho Forum, an organization pushing for innovation in e-commerce security, and is also CISO for a large, global chemicals corporation.

Comments

Post new comment

Login or register to link comments to your user profile, or you may also post a comment without being logged in.
The content of this field is kept private and will not be shown publicly.
Enter the fully qualified URL, eg. http://www.example.com/
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.

More information about formatting options

Additional Resources
Newsletter Subscription
Sign up for our CSO Online newsletters!
RSS Feeds
Syndicate content
 
Whitepaper

LANPlanner | Ensuring High Performance WLAN Networks

Learn how the Motorola LANPlanner facilitates prompt and precise planning and the design and measurement of robust 802.11a/b/g/n networks. Download this paper now to discover how to take wireless network performance to the next level.

Sponsored Links