Educause Security Discussion mailing list archives

Re: Flagging external emails and exceptions


From: "Childs, Aaron" <aaron () WESTFIELD MA EDU>
Date: Thu, 1 Oct 2020 13:50:20 +0000

Good Morning Beth,

We prepend a banner at the top of the body of external emails. You can see what we add below.  It was received with mix 
reviews, but has been effective for us.

Have a good day,
Aaron

[cid:image002.jpg@01D697D8.459B8B00]  Aaron Childs   Director
[cid:image003.jpg@01D697D8.459B8B00]
Infrastructure Services
Information Technology Services
Wilson Hall - 577 Western Ave. Westfield MA 01086
P  413.572.5527   F 413.572.5615
aaron () westfield ma edu<mailto:aaron () westfield ma edu>


From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU> On Behalf Of Beth Albertson
Sent: Wednesday, September 30, 2020 8:01 PM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: [SECURITY] Flagging external emails and exceptions


Caution External Email: This email originated outside of WSU. Do not click links, open attachments, or respond if it 
appears to be suspicious.
Colleagues,

We are thinking of flagging emails coming in external from our O365 tenant with either a red header at the top of each 
email or adding something like <EXTERNAL> to the subject line.  I wanted to ask other schools that are doing this 
whether they are adding exceptions for external organizations that are trusted.  For example, we use Jira, and I 
thought we could add this to an exception list.  Some have argued that maintaining such a list could be cumbersome and 
could potentially confuse users because some external emails would be flagged and others would not.  Does anyone have 
experience or thoughts on this matter?

Sincerely,

Beth Albertson, CISSP(r), PMP(r)
Director of Information Security
Western Washington University
beth.albertson () wwu edu<mailto:beth.albertson () wwu edu>

**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at https://www.educause.edu/community

**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at https://www.educause.edu/community


Current thread: