home
NEWS       BLOGS       FORUMS       NEWSLETTERS       RESEARCH       EVENTS       DIGITAL LIBRARY       CAREERS  
Network Computing Network Computing Powered by InformationWeek Business Technology Network

IMMERSE YOURSELF:

SOA

  |

Data Center

  |

802.11n

  |

Data Privacy

  |
APO  |

Virtualization

  |

NAC

  |

Security

  |

Network Mgmt

  |

Enterprise Apps

  |

Storage & Servers




Corporate.Net
workshop

Secure Electronic-Ma il: Return To Sender?


Securing Electronic-Mail Across Borders
Building a multivendor secure e-mail infrastructure requires careful planning. You need to consider the following policy issues in your strategy and product selection:

· Ownership and use of keys. Will the user or the corporation own the keys? Will a single pair be used both for signatures and encryption, or will separate pairs be maintained? Some products, such as Entrust Technologies' Entrust, Worldtalk Corp.'s Worldtalk Secure and OpenSoft Corp.'s O penSoft ExpressMail, allow for certificates containing two different pairs. Ent rust assumes corporate ownership of private encryption keys--so that data may be recovered--but personal signing keys are exclusively under the individual's control.

· Intrusiveness of encryption. Client-based e-mail security is usually implemented on a per-message basis. Does the organization trust its employees to recognize sensitive information? Can users be sufficiently trained to use encryption properly? How will long-term security awareness be maintained?

· Entrenched applications. How will an existing messaging platform be secured? Plug-ins for many MAPI and POP/IMAP mailers are available. Will emerging message access technologies--such as IMAP and browser access--be supported? Some S/MIME approaches may be incompatible with IMAP functions, and browser mail implementations let you download message parts for encryption or signature verification services.

· Integration to the corporate directory. Client products that enable public key distribution via the corporate directory a re far less cumbersome to manage than those that require peer relationships. For example, Netscape and Entrust let public LDAP-enabled directories retrieve certificates.

· Security administration roles. Does the system separate and enforce the roles of the security officer, system administrator, directory manager and user?

· Certificate authority policies. Will an internal or external CA be used? Which certificate authorities will be cross-certified? Will self-signed certificates and peer-trust relationships be allowed?

· Certificate policies. Under what verification criteria will a certificate be issued? What is the certificate's lifetime? How will Certificate Revocation Lists be used? What authentication is required before a certificate will be issued? Will certificates be distributed manually (via disk files), via e-mail or via Secure Sockets Layer (SSL) connections to a Web server?

· Client issues. How are certificates stored? What authentication mechanisms are used t o protect them? Can certificates be self-signed? Can a user establish a peer relationship with another user without formal cross-certification by a centralized authority?



Internet Rx
By Anthony Frey and Chris Lewis
IMAP Servers: Delivering a Brave, New Mailbox
By Greg Yerxa


Updated October 24, 1997






Ready to take that job and shove it?

Function:

Keyword(s):

State:
SPONSOR
RECENT JOB POSTINGS
CAREER NEWS
Go beyond Google and get vertical. These specialized search sites will help you find the business information you need -- fast.

Ari Balogh was named to the post of chief technology officer as the companys for a "realignment" of employees.










InformationWeek U.S. IT Salary Survey 2008
Salaries for business technology professionals are falling. Here's what you need to know in order to make good hiring decisions and personal career choices. Download Today
 
ROLLING RIGHT ALONG
Follow key Network Computing Reviews from conception to completion. This Week: Holistic APM.



Network Computing Reports Emerging Enterprise Podcast Series: Secrets to Success








TechSearch


Microsite of the Week


Powerful Information at Your Fingertips



InformationWeek Business Technology Network
InformationWeekInformationWeek 500InformationWeek 500 ConferenceInformationWeek AnalyticsInformationWeek CIO
InformationWeek EventsInformationWeek ReportsInformationWeek MagazinebMightyByte and SwitchDark Reading
Digital LibraryIntelligent EnterpriseInternet EvolutionNetwork ComputingNo JitterPlug Into The Cloud
space
Techweb Events Network
InteropVoiceConWeb 2.0 ExpoWeb 2.0 SummitEnterprise 2.0 ConferenceMobile Business ExpoSoftware ConferenceCSI - Computer Security Institute
Black HatGTECEnergy CampMashup CampStartup Camp
space
Light Reading Communications Network
Light ReadingLight Reading EuropeUnstrungLight Reading's Cable Digital NewsConstantinopleInternet EvolutionPyramid Research
Heavy ReadingLight Reading Live!Light Reading InsiderEthernet ExpoOptical ExpoTeleco TVTower Technology Summit
space
Financial Technology Network
Advanced TradingBank Systems & TechnologyInsurance & TechnologyWall Street & TechnologyAccelerating Wall StreetBank Systems & Technology Executive SummitBuyside Trading SummitInsurance & Technology Executive Summit
space
Microsoft Technology Network
MSDN MagazineTechNetThe Architecture Journal
space