|
Page 6 of 8
Email
5. Privacy and Security
Email messages are normally sent as plain text and could be read by a determined hacker. In the worst case, the content could be changed in transit or your identity forged.
5.1
Scramble the contents of private messages with the encryption feature that is part of most email software.
- Never transmit complete financial details within one unscrambled mail message.
- Set up your email software to keep copies of all messages you send.
- For very sensitive messages, use a separate high-security system, such as PGP.
5.2 Important messages, such as contract changes, should be signed with an authenticated signature that proves you are who you claim to be.
- Sophisticated email systems provide features to authenticate a message. If your system does not include authentication, you can use a separate software package.
- To implement authentication and signatures, you normally need to start with a special digital certificate, issued by a recognised authenticator (such as VeriSign
).
5.3 Include guidance on the monitoring and inspection of emails in your email policy.
|