Page 101 - Using MIS
P. 101
Then you start to think about security issues beyond internal email is encrypted. Educate users about the
email and data storage. What about losing data over instant importance of secure email, and encourage them
messaging, video conferencing, social media, Web searches, to use their corporate email account for all internal
malware (e.g., a computer virus), wireless networks, texting, communication.
or even visiting a simple Web site? Your head starts to spin. 2. Use a secure centralized file-sharing system, like Microsoft
There are a thousand ways to lose the R&D data you’re trying SharePoint, for all internal documents. SharePoint will
to protect. You contemplate locking the researchers in their give you greater control over your data and reduce data
offices with no communication with the outside world, but loss. Encrypt especially sensitive documents with third-
®
you’re pretty sure the CEO wouldn’t go for it. party software like 7-Zip . Discourage the use of external
Then you come to realize that the researchers will likely file storage services for internal projects.
resist the security changes you propose. Personally, you like 3. Install secure browsing software such as HTTPS
®
®
®
to share documents freely, email, chat, video conference, Everywhere , DNSCrypt , WOT , and possibly even a
®
and surf the Web. You’d be mad if someone started restrict- Tor browser for research that requires complete confi-
ing you. Making things more secure might make people less dentiality and anonymity.
productive. You’re going to bring that up to the CEO when As you’re walking down the hall with your action points
he asks if the company is “secure.” in hand, you start to really wonder if it’s even possible
Enough thinking. You need to start making a list of action to completely secure corporate communication and data
items for the CEO. There must be some technology that can sharing. Collaboration tools have many benefits, but they
help. You can’t be the only one facing these same issues. You do open the door to loss of critical assets.
email an old college friend who manages a large data center You may not have to completely secure all corporate
in the western United States. He gives you the following three communication. You may just need to make it more diffi-
suggestions to help secure your corporate communications:
cult for the bad guys to get into your systems than into your
1. Implement your own secure internal corporate email competitor’s systems. You don’t have to outrun the bear,
server, like Microsoft Exchange Server. Make sure all just your friends.
DisCussion Questions
1. In most circumstances, email or instant messages that addition, because mail is hosted on Google computers,
you send over a wireless device are open. Anyone with it is easy to access one’s email, contacts, and other data
some free software and a bit of knowledge can snoop from any computer at any location. Many employees
on your communications. In class, your professor could prefer using gmail to their corporate email system. What
read all of your email and instant messages, as could are the consequences to the organization of some em-
anyone else in the class. Does this knowledge change ployees doing most of their email via gmail? What are
your behavior in class? Why or why not? the risks?
2. Unless you are so foolish as to reveal personal data, such 4. Summarize the risks of using SharePoint Online in a
as credit card numbers, a Social Security number, or a business setting. How can organizations protect them-
driver’s license number in an email or instant message, selves from such risks? Is there any new risk here? After
the loss of privacy to you, as an individual, is small. all, organizations have been sharing data in other for-
Someone might learn that you were gossiping about mats with their business partners for years. Is this much
someone else, and it might be embarrassing, but that ado about nothing? Why or why not?
loss is not critical. How does that situation change for 5. Do you think the risks of using collaboration tools like
business communications? Describe losses, other than Google Drive, SharePoint Online, or Office 365 can be
those in this guide, that could occur when using email or so large that it makes sense for organizations to disallow
Google Drive. their use? Why or why not? What are the costs of disal-
3. In addition to Google Drive, Google offers gmail, a free lowing such use? How could an organization prevent an
email service with an easy-to-use interface and that employee from uploading data using a corporate com-
famous Google search capability. Using gmail, search- puter at work and then accessing that data from brows-
ing through past emails is easy, fast, and accurate. In ers on iPads or other mobile devices?
69