Find White Papers
Home
About Us
List Your Papers
    
> Sigaba > 5 Approaches to Messaging Security: A Technical Overview of the Tradeoffs

5 Approaches to Messaging Security: A Technical Overview of the Tradeoffs

White Paper Published By: Sigaba

This white paper reviews the five most common current approaches to messaging security. While the five approaches discussed here are not the comprehensive list of available solutions, they are the basis for most variations of messaging security solutions available today.



Tags : 
email security, security management, security policies, secure instant messaging, intranets, messaging, sigaba, security

Sigaba
Published:  Aug 21, 2009
Type:  White Paper
Length:  7 pages

The Five Approaches
to Messaging Security:
A Technical Overview
of the TradeoffsTechnical White Paper
1875 S. Grant Street, 10th Fl. | San Mateo, CA 94402 | (800) 475-8226 | www.sigaba.comSIGABA | WHITE PAPER | THE FIVE APPROACHES TO MESSAGING SECURITY: A TECHNICAL OVERVIEW OF THE TRADEOFFS | TABLE OF CONTENTS
The Five Approaches to Messaging Security:
Introduction 3 Criteria 3 Password-Based approach 4Public Key-Based Approach 4PGP-Based Approach 5Web-Based Approach 5Key Server Approach 6Conclusion 7 All information in this document is subject to change without notice. This document is provided for informational purposes only and Sigaba® makes no warranties, either express or implied, in this document.SIGABA | WHITE PAPER | THE FIVE APPROACHES TO MESSAGING SECURITY: A TECHNICAL OVERVIEW OF THE TRADEOFFS | PAGE 3
INTRODUCTION organizations must be able to audit the successful As businesses continue to rely more on digital delivery and authorized access of the data. Many communication channels, especially via the Internet, it regulations require that an organization have a record becomes increasingly important to protect the privacy of access to its con?dential data.of communicators. Cryptography, used in securing Ease-of-Usedata, is certainly not a new concept and neither is Ease-of-use up to this point has been the biggest obstacle its application in digital communication. What is a to successful messaging security system deployment. A recent phenomenon, however, is the sophisticated requirement criteria imposed on messaging security successful solution must be easy to use by all affected
solutions. This white paper reviews the ?ve most parties: easy to use by end users, easy to maintain by IT
common current approaches to messaging security. administrators, and easy to implement and deploy by IT
While the ?ve approaches discussed here are not the developers and system integrators.
comprehensive list of available solutions, they are the Ef?ciencybasis for most variations of messaging security solutions A successful messaging security solution must be available today. ef?cient enough to scale as the needs for the usage Throughout this document, the term "sender" speci?es grows. This means two things: predictable scalability the entity that initiates the transmission of secure data and economy of scale. The usage statistic must be an and it refers to a human user, an application, or both. accurate proxy to reliably predict the required system Similarly, the term "recipient" speci?es the entity that is sizing. As the number of users grows, the average cost on the other end of the transmission of secure data and per user should decrease to achieve economy of scale.it also refers to a human user, an application, or both. ExtensibilityCRITERIA A successful messaging security solution must be able The main purpose of messaging security is privacy of to extend the security resource to multiple applications. data. Achieving this objective on a practical enterprise Con?dential data reside and travel through many scale requires strong security, ease-of-use, and wide different applications, including email, instant reach. The following is a list of seven criteria that are messaging, and ?le transfers. The organization must be essential to realize these three requirements. able to leverage its investment in the messaging security solution for usage for multiple applications. Data EncryptionEncryption of data provides protection from unwanted Expandabilitythird-party access to the data. This is achieved through Much of business communication of sensitive data proper implementation of an encryption algorithm, such takes place between an organization and its partners, as AES, with strong authentication and access control. vendors, and key customers. Because daily business requires dynamic changes in business relationships Sender Control and each organization has its own information security Enterprises are sending internal data to external policies, secure communication channels must be easily destinations. The data is owned by the sending expandable to other organizations and also be easily organizations. As the owners of the data, the sending modi?able to accommodate changes. This ability to let organizations reserve the right to determine who, when, different authentication syste... [download for more]

Browse Technology Topics

Data Center

Virtualization, Cloud Computing, Infrastructure, Design and Facilities, Power and Cooling, Green Computing  
    

Data Management

Application Integration, Analytical Applications, Business Intelligence, Configuration Management, Database Development, Data Integration, Data Mining, Data Protection, Data Quality, Data Replication, Database Security, EDI, SOAP, Service Oriented Architecture, Web Service Management, Data Warehousing  
    

Enterprise Applications

Application Integration, Application Performance Management, Best Practices, Business Activity Monitoring, Business Analytics, Business Integration, Business Intelligence, Business Management, Business Metrics, Business Process Automation, Business Process Management, Call Center Management, Call Center Software, Change Management, Corporate Governance, Customer Interaction Service, Customer Relationship Management, Customer Satisfaction, Customer Service, EBusiness, Enterprise Resource Planning, Enterprise Software, EProcurement, Extranets, Groupware Workflow, HIPAA Compliance, IP Faxing, IT Spending, Marketing Automation, Performance Testing, Product Lifecycle Management, Project Management, Return On Investment, Risk Management, Sales & Marketing Software, Sales Automation, Server Virtualization, Simulation Software, Supply Chain Management, System Management Software, Total Cost of Ownership, Video Conferencing, Voice Recognition, Voice Over IP, Workforce Management, Incentive Compensation, Spend Management, Manufacturing Execution Systems, International Computing  

Human Resource Technology

Human Resources Services, Payroll Software, Time and Attendance Software, Workforce Management Software, Financial Management, Employee Monitoring Software, Employee Training Software, Recruiting Software/Services, Employee Performance Management, ELearning, Benefits Management, Expense Management  
    

IT Career Advancement

Cisco Certification, Microsoft Certification, Linux Certification, Network Security Certification, Software Development Certification  

IT Management

Employee Performance, ITIL, Productivity, Project Management, Software Compliance, Sarbanes Oxley Compliance, Service Management, Desktop Management  
    

Knowledge Management

Collaboration, Collaborative Commerce, Contact Management, Content Delivery, Content Integration, Content Management System, Corporate Portals, Customer Experience Management, Document Management, Information Management, Intranets, Messaging, Records Management, Search And Retrieval, Search Engines, Secure Content Management, SLA  

Networking

Active Directory, Bandwidth Management, Convergence, Distributed Computing, Ethernet Networking, Fibre Channel, Gigabit Networking, Governance, Grid Computing, Infrastructure, Internetworking Hardware, Interoperability, IP Networks, IP Telephony, Local Area Networking, Load Balancing, Migration, Monitoring, Network Architecture, Network Management, Network Performance, Network Performance Management, Network Provisioning, Network Security, OLAP, Optical Networking, Quality Of Service, Remote Access, Remote Network Management, Server Hardware, Servers, Small Business Networks, TCP/IP Protocol, Test And Measurement, Traffic Management, Tunneling, Utility Computing, VPN, Wide Area Networks, Green Computing, Cloud Computing, Power and Cooling, Data Center Design and Management, Colocation and Web Hosting  
    

Platforms

AS/400, Domino, Linux, Microsoft Exchange, Oracle, PeopleSoft, SAP, Siebel, Solaris, Tivoli, Unix, Web Sphere, Windows, Windows Server  

Security

Access Control, Anti Spam, Anti Spyware, Anti Virus, Application Security, Auditing, Authentication, Biometrics, Business Continuity, Compliance, DDoS, Disaster Recovery, Email Security, Encryption, Firewalls, Hacker Detection, High Availability, Identity Management, Internet Security, Intrusion Detection, Intrusion Prevention, IPSec, Network Security Appliance, Password Management, Patch Management, Phishing, PKI, Policy Based Management, Security Management, Security Policies, Single Sign On, SSL, Secure Instant Messaging, Web Service Security, PCI Compliance, Vulnerability Management  
    

Software Development

.NET, C++, Database Development, Java, Middleware, Open Source, Software Outsourcing, Quality Assurance, Scripting, SOAP, Software Testing, Visual Basic, Web Development, Web Services, Web Service Security, XML  

Storage

Backup And Recovery, Blade Servers, Clustering, IP Storage, ISCSI, Network Attached Storage, RAID, Storage Area Networks, Storage Management, Storage Virtualization, Email Archiving, Data Deduplication  
    

Wireless

802.11, Bluetooth, CDMA, GPS, Mobile Computing, Mobile Data Systems, Mobile Workers, PDA, RFID, Smart Phones, WiFi, Wireless Application Software, Wireless Communications, Wireless Hardware, Wireless Infrastructure, Wireless Messaging, Wireless Phones, Wireless Security, Wireless Service Providers, WLAN  
Search