Security Basics mailing list archives

RE: Internet E-mail monitoring/approval


From: "dave" <dave () netmedic net>
Date: Thu, 10 Apr 2003 23:00:10 -0400

Ted,

This can be done, but how many clients are we talking about??

Can you imagine how long it would take to read say 3 e-mails per client on a
100 user system??

Yes it is true  " Also, it is my
understanding that e-mail sent using a company's e-mail system is
considered the property of that organization and therefore the
organization can do with it what they want.  If I am mistaken in this
then please let me know."

But you have to be careful and post warnings such as:

Confidentiality: The information contained in this e-mail message and
attached files are confidential and intended only for the use of the
individual or entity named above.  If the reader of the message is not the
intended recipient, you are hereby notified that any dissemination,
distribution, or copying of this e-mail message is prohibited.  If you have
received this e-mail message in error, please immediately notify us by
replying to the sender or by telephone and delete the message(s) and all
attachments.

Privacy Notice:  This e-mail comes from a Monitored E-mail system; users
have no explicit or implicit expectation of privacy.  Any or all E-mails and
all files sent through this system may be intercepted, monitored, recorded,
copied, audited, inspected, and disclosed to authorized site, and law
enforcement personnel, as well as authorized officials of other agencies.
By using this e-mail system, the user consents to such interception,
monitoring, recording, copying, auditing, inspection, and disclosure at the
discretion of authorized site personnel.

Employer Liability: Our Company accepts no liability for the information
contained in this e-mail or for the consequences of any action taken based
on the information provided, unless that information is subsequently
confirmed in writing.  The information contained herein does not necessarily
express the opinion or position of the Company and cannot be attributed to
or made binding upon the Company.

This would have to be part of each users e-mail signature and a warning on
the system when they sign on to a workstation such as:

This is a Private computer system.  It is for authorized use only.  Users
(authorized or unauthorized) have no explicit or implicit expectation of
privacy.  Any or all uses of this system and all files on this system may be
intercepted, monitored, recorded, copied, audited, inspected, and disclosed
to authorized site, and law enforcement personnel, as well as authorized
officials of other agencies.  By using this system, the user consents to
such interception, monitoring, recording, copying, auditing, inspection, and
disclosure at the discretion of authorized site personnel.  Unauthorized or
improper use of this system may result in administrative disciplinary action
and civil and criminal penalties.  By continuing to use this system you
indicate your awareness of and consent to these terms and conditions of use.
LOG OFF IMMEDIATELY if you do not agree to the conditions stated in this
warning.

With this on all systems then the user knows the implications, and agrees to
it.

I would definitely run it by the legal department first, and take the time
consideration into account of reading every e-mail.



 
_____________________
Dave Kleiman
dave () netmedic net
www.netmedic.net

 






-------------------------------------------------------------------
Is SPAM over-loading your e-mail server, disk space or bandwidth?
SurfControl E-Mail Filter is flexible, intelligent and policy-driven
protection.
http://www.securityfocus.com/SurfControl-security-basics2
Download your free fully functional trial, complete with 30-days of free technical support.
Stop SPAM before it stops you.
-------------------------------------------------------------------


Current thread: