Information security considerations for electronic messaging should include the following:
a) protecting messages from unauthorized access, modification or denial of service
commensurate with the classification scheme adopted by the organization;
b) ensuring correct addressing and transportation of the message;
c) reliability and availability of the service;
d) legal considerations, for example requirements for electronic signatures;
e) obtaining approval prior to using external public services such as instant messaging,
social networking or file sharing;
f) stronger levels of authentication controlling access from publicly accessible
networks.
There are many types of electronic messaging such as email, electronic data interchange and
social networking which play a role in business communications. (NL ISO/IEC, 2015)
5. Mobile Device Policy
Mobile devices include smartphones and tablets. These devices have internal memory or
removable memory cards that can hold a significant
“App stores and mobile apps are the
amount of data. Data can include email with
greatest hostile code and malware
attachments, contacts, and scheduling information.
delivery mechanism ever created.”
Additionally, many devices include applications that
allow users to read and manipulate different types
– Winn Schwartau – Chairman of
of documents.
mobileactivedefense.com
Organizations often purchase smartphones for users and maintain their data plans. This is
certainly a great benefit for the employee, but it also gives the organization additional control
over the user’s phone and the data it contains. Some of the common controls organizations
enable on user phones are encryption, screen lock, Global Positioning System (GPS) , and remote
wipe. Encryption protects the data if the phone is lost or stolen, the screen lock slows down
someone that may have stolen a phone, and GPS provides information on the location of the
phone if it is lost or stolen. A remote wipe signal can be sent to a lost device to delete all data
on the device if it has been lost and includes valuable data. Many devices respond with a
confirmation message when the remote wipe has succeeded. (Stewart et al., 2004)
A policy and supporting security measures should be adopted to manage the risks introduced
by using mobile devices. When using mobile devices, special care should be taken to ensure
that business information is not compromised. The mobile device policy should take into
account the risks of working with mobile devices in unprotected environments .
The mobile device policy should consider:
a) registration of mobile devices;
b) requirements for physical protection;
Lebanese National Security Policy Guidelines v1.7
Page
28 |