by Sandra Vaughan, special to Network World

E-mail encryption: It’s easier than you think

How-To
Jul 23, 20086 mins

In order to properly secure confidential information — everything from trade secrets to financial data and personal identity information — corporations need policy-based e-mail encryption.

But securing data in motion hasn’t yet achieved critical mass. In a March survey of e-mail decision makers at more than 400 large enterprises, Proofpoint asked respondents what percentage of e-mail that should be encrypted is actually being sent that way. On average, the answer is “less than half.” Furthermore, a quarter of respondents said they “don’t know” the answer to the question.

Even though 35% of survey respondents said they intend to deploy a policy-based encryption solution, concerns around administrative burdens, infrastructure costs, ease-of-use and effectiveness have made some organizations hesitant to take the plunge.

The reality is that traditional encryption solutions — which require extensive storage and backup, daunting key management requirements and significant end-user training — have been outpaced by approaches that are easy to administer and use, and, most importantly, allow employees to continue to use e-mail but in a secure fashion.

Safeguarding private information

Few organizations are immune from today’s regulatory mandates, many of which require organizations to deploy e-mail encryption as part of their messaging security architecture. The Health Insurance Portability and Accountability Act (HIPAA), Gramm-Leach-Bliley Act, Federal Information Security Management Act and many individual state laws provide guidelines for implementing best practices for handling private information via e-mail and other electronic communications. However, regulatory compliance concerns are only part of the reason encryption solutions should be a component of an organization’s overall messaging security architecture.

A quick hit of the “send” button could result in a competitor getting hold of confidential product-launch plans, the exposure of customer Social Security numbers, a premature leak of corporate financial information or patient medical records being revealed to the masses. The financial and legal ramifications of these situations would be enormous, not to mention the potential negative impact on an organization’s reputation.

The primary role of an encryption solution is to:

• Keep sensitive information private.

• Prevent tampering of messaging content.

• Authenticate the identity of the message’s sender and recipient.

Training users on the proper use of encryption systems can be a significant barrier to the successful deployment of traditional secure messaging solutions. The ideal encryption solution should eliminate the need for users to take any special actions in order to securely communicate electronically with individuals outside of the organization.

Automatically applying encryption based on customized messaging security policies allows organizations to secure messages that contain private or confidential information without requiring manual intervention by message senders.

Today’s e-mail-based, data-loss prevention systems can scan messages and their attachments for the presence of personal identifiers — such as Social Security, credit card, bank account or medical record numbers — either alone or in combination with healthcare terms such as drug, disease and treatment terms or codes. If such information is detected (possibly taking into account other factors such as the sender’s role or the message destination), message disposition policies can be applied. These policies can range from “block the message and flag it for review” to “encrypt the message and send it securely before transmission.”

In this way, compliance and content security policies are consistently and accurately applied on an as-needed basis, giving IT the greatest control, without inhibiting the use of e-mail as a business tool. This enables users to:

• Send encrypted messages using existing messaging infrastructure.

• Send encrypted messages to individuals with whom they’ve never corresponded.

• Easily encrypt e-mail attachments.

• Read, reply and forward secure messages.

Automating encryption based on messaging policies enables secure e-mail communication that’s as simple as the following:

Step 1: Doctor Dan sends an e-mail to Patient Pete using his regular e-mail client. The message is analyzed and automatically encrypted based on the presence of protected health information.

Step 2: Patient Pete receives the encrypted e-mail and clicks on an embedded link to a secure server where the recipient authenticates by providing some type of credentials. This might be as simple as providing a login and password or it could require the recipient to enroll. Enrollment procedures vary widely, but are often similar to adding a new account at on online retailer (with the exception that only a previously known e-mail would be allowed to enroll).

Step 3: The message is decrypted and hosted in server memory for Patient Pete to review. After Patient Pete accesses the message, it is removed from memory.

Step 4: Patient Pete can securely respond to Doctor Dan.

An encryption checklist for IT

When looking for a powerful encryption solution, organizations should look for a solution that is easy to implement and easy to manage, without the overhead and costs associated with traditional security solutions. When investigating encryption solutions, IT security professionals should run through the following checklist:* High detection accuracy: Confidential, private and regulated content should be automatically detected and encrypted, without instances of false positives.

* Policy driven: Encryption should be automatically based on customizable compliance and content security policies.

* Easy to use: Encrypted communication should mirror how individuals communicate today, without requiring software downloads or the management of digital certificates and encryption keys, while enabling individuals to view encrypted messages through an easy-to-use interface or desktop client.

* Granular encryption policies: It should be possible for encryption to be triggered by a variety of data matches including structured data (such as credit card numbers and Social Security numbers); unstructured data (such as confidential data in a product launch plan); and by message origin, destination and attributes, such as attachment type.

* Low cost of ownership: The ideal encryption solution should eliminate the need for extensive storage, backup and recovery overhead.

Powerful, policy-driven encryption allows organizations to mitigate the risks associated with regulatory violations, data loss and corporate policy violations. Encryption solutions have evolved, and properly protecting your organization’s confidential and sensitive data while still making the information readily available to the appropriate individuals just may be easier than you think.

Vaughan is senior vice president of marketing and products for e-mail security and data loss prevention vendor, Proofpoint, Inc. Visit the company at www.proofpoint.com/outbound.