Find White Papers
Home
About Us
List Your Papers
    
> C2C Systems, Inc. > Compliance Archives: Can You Prove Your Email Integrity?

Compliance Archives: Can You Prove Your Email Integrity?

White Paper Published By: C2C Systems, Inc.

This paper considers the use of email archives for compliance. It will also review how archives are trusted and look at what has to be done to ensure that integrity is maintained throughout the chain of events that take place within an email archive environment.



Tags : 
compliance, email archiving, data quality, records management, personal email, enterprise email, email security, c2c

C2C Systems, Inc.
Published:  Mar 15, 2007
Type:  White Paper
Length:  7 pages







Compliance Archives
Can You Prove Your Email Integrity?

Permissions Vulnerabilities with Compliance

Introduction
This paper considers the use of email archives for compliance. It will also review how archives are trusted and look at what has to be done to ensure that integrity is maintained throughout the chain of events that take place within an email archive environment.







Disclaimer of liability: While every precaution has been taken in the preparation of this document, C2C Systems assumes no responsibility for errors or omissions, or for damages resulting from the use of the information contained herein. Why do email compliance archives exist?
Email compliance archives provide a reliable record of internal and/or external communications and provide potential evidence or other critical records, quickly and cost effectively.
Email archives exist to help organizations of all types, all sizes and in all countries to meet the growing demands of government, industry and internally generated regulations that have grown into being during the post-Enron era. Although the scope and value of some of the new legislation is questioned, due to its impact on international trade, company ownership and national tax revenues, it appears that compliance-driven archiving is here to stay.
Archive technologies are becoming more cost effective every year as they prove to provide many obvious benefits to organizations. These include:
. Proof and accountability in instances of specific legal actions around the new compliance laws . Tools for good business governance and ethical audits of business practices
Data sources that can enable an organization to leverage information flows and information records in new ways. For example, analysis can provide businesses with specific competitive advantages based on the actual actions of their staff in their daily activities.
Chain of trust
A compliance archive has to be a 'trusted' source of information about the organization, especially because of its potential legal uses. Normally, this archive is created directly from the source or main transport mechanism of the information, such as the email or calendar system. The archive process makes copies of all information, indexes it (for rapid search and retrieval at any later time) and places onto some form of storage.
The process of maintaining an email archive can be considered a 'chain':
. A new user is given an email identity . The user writes an email and sends it via the email system . This email is transported by the email system and copied by an archiving solution. (It is also placed into an email system mailbox to be read) . The archive solution places a copy of the email on a storage device to provide a permanent record
So long as the archive holds a trusted copy of the original, the communication or other data the information from the archive has validity for internal audit, to meet best practice and legislative guidelines and as legal evidence.
For the email Archive to be valid, and trusted, all parts of the chain have to be trusted.
The first links in the chain depends on the security settings of the email system itself.
Other links, including in some cases the compliance archive itself, depend on exact rights and permissions settings for the email system.
The trust of the final link, the storage media itself, is often addressed by the use of WORM drive. These are devices from which data can be read many times but which can not be altered hence the Write Once Read Many acronym (WORM).
2006 Copyright C2C Systems Page 2/7 The trust of the mail system depends on standard access controls for mail servers and administrators. For example, Microsoft Exchange has a set of permissions to control exactly who is able to have access to which email storage areas and mailboxes. These are regularly reconfigured to help administrators cope with day-to-day events such as people moving departments or leaving the company.
At least 40% of mailbox permissions will change every year in a typical organization with a staff turnover of 15% and a 25% role change rate - an arduous task for adminis... [download for more]

Browse Technology Topics

Data Center

Virtualization, Cloud Computing, Infrastructure, Design and Facilities, Power and Cooling, Green Computing  
    

Data Management

Application Integration, Analytical Applications, Business Intelligence, Configuration Management, Database Development, Data Integration, Data Mining, Data Protection, Data Quality, Data Replication, Database Security, EDI, SOAP, Service Oriented Architecture, Web Service Management, Data Warehousing  
    

Enterprise Applications

Application Integration, Application Performance Management, Best Practices, Business Activity Monitoring, Business Analytics, Business Integration, Business Intelligence, Business Management, Business Metrics, Business Process Automation, Business Process Management, Call Center Management, Call Center Software, Change Management, Corporate Governance, Customer Interaction Service, Customer Relationship Management, Customer Satisfaction, Customer Service, EBusiness, Enterprise Resource Planning, Enterprise Software, EProcurement, Extranets, Groupware Workflow, HIPAA Compliance, IP Faxing, IT Spending, Marketing Automation, Performance Testing, Product Lifecycle Management, Project Management, Return On Investment, Risk Management, Sales & Marketing Software, Sales Automation, Server Virtualization, Simulation Software, Supply Chain Management, System Management Software, Total Cost of Ownership, Video Conferencing, Voice Recognition, Voice Over IP, Workforce Management, Incentive Compensation, Spend Management, Manufacturing Execution Systems, International Computing  

Human Resource Technology

Human Resources Services, Payroll Software, Time and Attendance Software, Workforce Management Software, Financial Management, Employee Monitoring Software, Employee Training Software, Recruiting Software/Services, Employee Performance Management, ELearning, Benefits Management, Expense Management  
    

IT Career Advancement

Cisco Certification, Microsoft Certification, Linux Certification, Network Security Certification, Software Development Certification  

IT Management

Employee Performance, ITIL, Productivity, Project Management, Software Compliance, Sarbanes Oxley Compliance, Service Management, Desktop Management  
    

Knowledge Management

Collaboration, Collaborative Commerce, Contact Management, Content Delivery, Content Integration, Content Management System, Corporate Portals, Customer Experience Management, Document Management, Information Management, Intranets, Messaging, Records Management, Search And Retrieval, Search Engines, Secure Content Management, SLA  

Networking

Active Directory, Bandwidth Management, Convergence, Distributed Computing, Ethernet Networking, Fibre Channel, Gigabit Networking, Governance, Grid Computing, Infrastructure, Internetworking Hardware, Interoperability, IP Networks, IP Telephony, Local Area Networking, Load Balancing, Migration, Monitoring, Network Architecture, Network Management, Network Performance, Network Performance Management, Network Provisioning, Network Security, OLAP, Optical Networking, Quality Of Service, Remote Access, Remote Network Management, Server Hardware, Servers, Small Business Networks, TCP/IP Protocol, Test And Measurement, Traffic Management, Tunneling, Utility Computing, VPN, Wide Area Networks, Green Computing, Cloud Computing, Power and Cooling, Data Center Design and Management, Colocation and Web Hosting  
    

Platforms

AS/400, Domino, Linux, Microsoft Exchange, Oracle, PeopleSoft, SAP, Siebel, Solaris, Tivoli, Unix, Web Sphere, Windows, Windows Server  

Security

Access Control, Anti Spam, Anti Spyware, Anti Virus, Application Security, Auditing, Authentication, Biometrics, Business Continuity, Compliance, DDoS, Disaster Recovery, Email Security, Encryption, Firewalls, Hacker Detection, High Availability, Identity Management, Internet Security, Intrusion Detection, Intrusion Prevention, IPSec, Network Security Appliance, Password Management, Patch Management, Phishing, PKI, Policy Based Management, Security Management, Security Policies, Single Sign On, SSL, Secure Instant Messaging, Web Service Security, PCI Compliance, Vulnerability Management  
    

Software Development

.NET, C++, Database Development, Java, Middleware, Open Source, Software Outsourcing, Quality Assurance, Scripting, SOAP, Software Testing, Visual Basic, Web Development, Web Services, Web Service Security, XML  

Storage

Backup And Recovery, Blade Servers, Clustering, IP Storage, ISCSI, Network Attached Storage, RAID, Storage Area Networks, Storage Management, Storage Virtualization, Email Archiving, Data Deduplication  
    

Wireless

802.11, Bluetooth, CDMA, GPS, Mobile Computing, Mobile Data Systems, Mobile Workers, PDA, RFID, Smart Phones, WiFi, Wireless Application Software, Wireless Communications, Wireless Hardware, Wireless Infrastructure, Wireless Messaging, Wireless Phones, Wireless Security, Wireless Service Providers, WLAN  
Search