Voltage enables AD groups to be used for e-mail security rules triggers

Opinion
Jun 14, 20063 mins

* Voltage upgrades its identity-based encryption system

If you happen to be at Microsoft’s TechEd event this week, try to stop by the Voltage Security booth for a look at the latest release (Version 3) of Voltage SecureMail Desktop.

Voltage pioneered identity-based encryption (IBE) a few years ago (see “Start-up aims to ease sending and receiving encrypted mail”) and has continued to enhance and expand the uses of the technology. Early on, it discovered that users didn’t always make good decisions about when to encrypt messages, but enterprises want to be able to centrally define encryption policies, ensuring that sensitive data will be protected without active user intervention.

The currently shipping version of the SecureMail Desktop, Version 2.0, introduced rules-based encryption capabilities to enable centralized management of mandatory encryption policies. Administrators could easily define rules that specified, for example, that all messages sent to users in a particular domain (e.g., “anycompany.com”) must be encrypted. However, the rule triggers were limited to string pattern matches against the sender or recipient e-mail addresses (e.g., the rule could only encrypt to “*@anycompany.com”).

Version 3.0 extends these capabilities by enabling Active Directory groups to be used as the rule triggers. Now, for example, administrators can centrally enforce that all messages sent from a user within the HR group to a user within the finance group must be encrypted. Rules can contain multiple triggers and support both AND and OR combinations. Even disconnected users are protected, because there’s full offline support for group-based encryption rules provided via Microsoft Outlook’s Offline Address Book. Even without a network connection, rules will be automatically enforced, ensuring the privacy of information in all situations.

This new version also adds what the company calls “Secure Conversations.” While enterprises can generally control the flow of data within their corporate boundaries, protecting data once it has been sent to an external party has traditionally been difficult. Secure Conversations is a new feature designed to provide downstream security of content that’s deemed sensitive. Secure Conversations automatically requires that any reply or forward of a secure message must also be sent securely. Secure Conversations can be enabled both for internal client deployments as well as external ones. With Secure Conversations, no longer can a downstream user inadvertently expose sensitive data. Once a user has deemed that a given “conversation” requires security, all subsequent messages in that conversation will be automatically encrypted.

By the way, if you aren’t at TechEd (and I’m one of the unfortunates who isn’t as I’m 3,000 miles away at the Burton Group’s Catalyst conference) you should visit the Voltage Web site for all the details. While you’re there, be sure to register for the free 30-day test drive of SecureMail. It might be just what your chief security officer has been looking for.