Site Sponsor:

mcafee_logo.gif
line

Now Available:

Featured Resource:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Dan or post a comment to the blog.

« Controlling Messaging Services - Acquistions and Implementation | Main | COBIT and Governance Best Practices »

Controlling Messaging Services - Delivery and Support

This entry continues the review of management controls for messaging security. We're using COBIT as a best practice guide, and in the case of delivery and support, many of the control objectives that apply to overall IT governance are right on the mark for controlling messaging services.

Defining and managing service levels seems like an obvious step to introducing any new service but it's easy to overlook sometimes. Take for example the way instant messaging works its way into organizations. Staff start using free IM services for obvious reasons, groups of users grow and at some point it gets on the IT radar. Now in the best of all possible worlds, it gets on the radar because management sees IM as a productivity tool they can leverage. Sure that does happen, but so can another scenario.

IM has compliance implications for some organziations. Uncontrolled, unsecure IM servcies can introduce malware, provide unmonitored means to leak information, and lead to all kinds of headaches when the records retention folks come around looking for copies of IM conversations.

Grass roots adoption of technology is great. The trick is watching for that critical mass when that new technology has to be controlled. When that happens don't forget to think about service level agreements, along with all the other issues you'll have to address.

TrackBack

TrackBack URL for this entry:
http://www.realtime-websecurity.com/type/mt-tb.cgi/85

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Dan Sullivan's Bio:

Dan Sullivan is a systems architect with 20 years of IT experience that includes engagements in enterprise security, application design, and systems architecture. His experience includes a broad range of industries, including financial services, manufacturing, government, retail, gas and oil production, power generation, and education. Dan’s security-related project work has ranged from requirements analysis for enterprise information security to designing and implementing security for database applications and enterprise portals. Dan has written about information security and other enterprise information management topics for Business Security Advisor, DM Review, Intelligent Enterprise, and E-Business Advisor. You can contact Dan at: dan_sullivan@realtimepublishers.net