Posts

Showing posts with the label security

Email Retention Policies

Many companies have little to no email retention policies in place.  The idea here is to ensure that if a business related email is required, it can be recovered for up to a 6 year period. However it has also been raised  that 6 years may not actually be sufficient when projects which are completed over a long period of time are concerned.  Therefore 6 yrs from time of project completion should be the consideration.  In some cases financial data may need a slightly longer period of retention to match other financial requirements. The question is how do you manage this type of thing.  Users have the ability to delete their emails etc and therefore relying on users to manage their own mailboxes completely may not be the best option. Many companies opt for an email archiving solution which provides a copy of every email in and out to be stored safely and all access to these stored messages audited for compliance. With the adoption of cloud email services thi...

SHA-1 Certificates will be rejected by the latest browsers.

Websites and systems protected using certificates using Sha-1 algorithms will no nonger be accepted by new browsers.  IE11 and Chrome for example wont allow a user to continue on to the site regardless. Most public CA's have been issuing more scure certificates for some time now, however many internal CA's are still using Sha-1 to sign their certificates. Its time to check and upgrade/reconfigure  if you want your systems to keep running smoothly. Microsoft for example has several articles on how to deal with the situation in their support site. I recently helped a customer running Windows Server 2008 Domain to upgrade their CA to issue the higher security certs.