Policies driving messaging security and compliance

Opinion
Jun 29, 20062 mins

* Policy is the foundation for all things messaging

We’re about to start a major study on messaging policy management practices in North American organizations to discover how policies will shape the future of e-mail, instant messaging, security, archiving, compliance and other aspects of messaging management.

In our just published study on messaging security, for example, we found that two-thirds of organizations have a need to implement company-specific policies for compliance. For example, most organizations cited a need to enforce a variety of policies using a content-filtering solution, such as acceptable use policies focused on harassing or profane language, detecting loss of intellectual property or other sensitive information, and detecting the transmission of protected health information in compliance with HIPAA regulations.

One of the problems with policy management for many organizations is that policies impact, and need to be driven by, various parts of an organization, including legal, human resources, finance, executive management, etc., but IT is typically called upon to implement and manage these policies. In our security study, nearly one-half of organizations told us that their IT function would like senior business managers to be more involved in managing policies for things like protecting against the loss of intellectual property and for regulatory compliance. Further, IT would like the organizations most impacted by specific policies to be more involved in enforcing these policies.

What is needed, therefore, are policy creation and enforcement tools that can allow non-IT staff members to participate in the development and management of policies. I’d like to hear from you with regard to how difficult policies are to create, manage and enforce in your organization; and where you feel that vendors need to concentrate in developing solutions that can best meet your needs. Please drop me a note.