Welcome | Sign In
TechNewsWorld.com
Trends

SPECIAL REPORT
E-Mail and Instant Messaging Face Compliance Challenges

Print Version
E-Mail Article
Reprints
E-Mail and Instant Messaging Face Compliance Challenges

Regulations imposed by the Securities Exchange Commission, the Freedom of Information Act and Sarbanes-Oxley make no distinction between public instant-messaging clients provided by AOL, MSN, ICQ and Yahoo and the enterprise-messaging systems provided by Microsoft Live Communications Server and IBM Lotus Instant Messaging.


How Much is 'Free' Costing You?
Learn how DaveRamsey.com saw a 567% uplift in ROI with Omniture. This complimentary guide and webinar cover the most important factors in selecting an analytics solution. Download Now.

In the financial workplace, e-mail and instant messaging (IM) are becoming essential enterprise tools. Once the province of teens chatting with their friends, instant messaging is now relied on by brokerage firms and other financial companies to maintain contact with clients. An ever-increasing number of government regulations and industry-specific rules make compliance with secure-messaging criteria mandatory.

According to analyst firm Giga Information Group, 60 percent or more of large companies use some form of instant messaging, but 90 percent of those companies have no formal IT support, and fewer than 10 percent have implemented secure, enterprise messaging.

Regulations imposed by the Securities Exchange Commission, the Freedom of Information Act and Sarbanes-Oxley make no distinction between public instant-messaging clients provided by AOL, MSN, ICQ and Yahoo (Nasdaq: YHOO) and the enterprise-messaging systems provided by Microsoft (Nasdaq: MSFT) Live Communications Server and IBM (NYSE: IBM) Lotus Instant Messaging. Regardless of the platform, financial institutions that fail to meet security compliance mandates can face significant financial and legal liabilities.

Perhaps the most stringent of the regulations involves storing electronic messages. That can cause unique problems because e-mail Increase Customer Sales with Email Marketing -- Free Trial from VerticalResponse and messaging clients are not typically integrated into one common application. Those two separate functions each have several obstacles in meeting compliance regulations.

"We have to keep all e-mail and instant-messaging conversations on site for three years and be able to fully search the content," Richard W. Smith, the IT director at R.W. Smith brokerage, told TechNewsWorld.

Mailstore One Compliance Solution

R.W. Smith's advisers handle 1,500 to 9,000 pieces of e-mail per day alone. With no written standards for e-mail clients, finding a suitable compliance solution was a Herculean chore. Smith researched several leading software technologies before selecting MailStore by Information Management Research (IMR) to handle its SEC compliance.

According to Smith, the product's default installation needed no fine tuning and the bulk storage costs were well under what other products cost, according to Smith.

"We are able to maintain 480 GB of archives for under US$10,000 per year. Other solutions had monthly maintenance costs of $7,500 plus an initial $5,000 set-up fee," Smith said.

A major selling point for Smith was the ability to transport archives to other database architectures from the propriety storage format of MailStore's own database. That, combined with an iron-clad security process that prevents clients from accessing the archives, makes compliance with SEC regulations worry free.

"It's worth its weight in gold," Smith said about his satisfaction with MailStore.

Tougher Than Other Industries

Dmitry Shapiro, CTO and founder of Akonix.com, said security regulations are much more demanding for financial institutions than for other industries. To comply with some of the more strict regulations, instant-messaging files must be stored in a write-once-read-many format like the kind used by CD recordable discs. Also, the financial institution must prove an audit trail for all stored records. Finally, firms must be able to access all messages and make the search results available to auditors.

"Instant messaging applications natively lack those abilities," he said. "So financial agencies must solve those archiving problems to meet SEC standards."

Akonix's answer to the IM-compliance regulations is L7 Enterprise, a software package available with a one-time user license and an annual fee. Shapiro said several factors make the L7 Enterprise package worth considering. For one, he said, L7 Enterprise is widely deployed with close to 400,000 users. Many of the product's users are not financial institutions but want a reliable way to lock down IM abuses by employees and want to be able to catalog the content of business conversations.

"It deals with security, regardless of whether or not SEC compliance is needed," he said. For example, Cingular Wireless uses the application at all of its locations, he said.

FDIC Policies

In July, the Federal Deposit Insurance Corporation (FDIC) issued its 5,300 member banks and financial institutions a warning about unmangaged instant-messaging access. Its "Guidance on Instant Messaging" warned that using popular consumer IM clients -- such as Yahoo, Microsoft's MSN Messenger and AOL's Instant Messenger -- can expose companies to security, privacy and legal liability risks.

Included in these risks are viruses and worms, illegal downloading of copyrighted material, loss of confidential information and identity theft. According to the FDIC recommendations, members should protect themselves against these vulnerabilities by establishing policies and implementing solutions to allow, restrict or deny IM use based on the individual need of the enterprise.

Akonix's L7 Enterprise provides users with security, management, reporting and regulatory compliance across both public and enterprise IM systems. This includes logging, auditing, reporting and archiving features to comply with FDIC, federal, industry and internal compliance rules for electronic communications.

Shapiro said the software, just like antivirus and other network-security products, must be updated regularly. That process is handled automatically through a resident live update module. "It also functions as IM proxy, setting a firewall between the instant-messaging client and the message source," he said.

The automatically updated filters in the L7 Enterprise application introduce a layer of network security against worms and viruses that otherwise could compromise computer systems by being hidden in instant-messaging traffic.


Print Version E-Mail Article Reprints More by Jack M. Germain


Talkback: Join the Discussion.
Which is why...
Justyn
Posted 2009-02-27
...we found it to be so important to work with an enterprise IM Client company who can respond ...

More by Jack M. Germain

Microsoft FOSSifies .Net Micro Framework
November 18, 2009
Microsoft has declared its .Net Micro framework open source under the Apace 2.0 license. Not all bits of .Net Micro are covered, however. Its TCP/IP stack has been stripped, as has its cryptography libraries. Rights to the TCP/IP stack aren't Redmond's to give, and the cryptography libraries are used outside of the scope of the .Net Micro framework, according to the company.
New Ubuntu OS Features Create Good Karma
November 13, 2009
Amidst the OS upgrades from Apple and Microsoft over the last few months, the Linux OS Ubuntu got a version bump of its own. Ubuntu 9.10, or Karmic Koala, is well worth the effort to upgrade, and its developers have made the process easier -- if you're using the full-sized desktop/notebook version. The Remix version, intended for netbooks, caused quite a few headaches.
Samsung Chimes In With Bada Mobile OS
November 11, 2009
With Android, iPhone, BlackBerry, WinMo, Symbian, WebOS and plenty other mobile platforms fighting for space, is there room for one more? Samsung believes there is, and it's announced a new open mobile platform called "Bada." The company, which already makes handsets for several existing platforms, says Bada will make app-making easy for developers. The first Bada handset should be out in the first half of 2010.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network