The risk of violations caused by the Sarbanes-Oxley Act [S-Ox] and spam in 2002.
The Sarbanes-Oxley Act aims to address the rise of corporate fraud in the early 21st century. In short, the Act sets the retention period for electronic data [seven years] and requires companies to create, publish and implement detailed policies governing the classification, access and control of electronic data, including email.
S-Ox does not specifically mention spam, spyware or any other malware, but it does address compliance issues that may arise from these issues. The purpose of the Act is to ensure that the company retains data that may be important to address legal issues. Company policy must ensure that data is not lost or deleted; security measures are designed to limit data access to parties that are legally needed; and when survey information is needed, data can be searched and retrieved in a meaningful manner. Spam can affect all of these priorities.
Retention cost
If you don't have enough spam filters, the cost of spam storage is significant for medium-sized or large companies that try to keep each email for seven years, because up to 90% of all emails from the Internet are currently junk. Mail [Spamhaus]].
Safety
According to the FBI, 74% of Internet and cybercrime cases use unsolicited e-mail as the primary means of contacting victim companies and individuals. Spam is the number one means of spreading malicious viruses, worms and Trojan horses designed to steal confidential information. If you do not provide adequate protection against these threats, or at least make serious and sensible efforts, you are eligible to become a violation of S-Ox.
access
Files contaminated with spam are more difficult to index by keyword, and it is more common to search for relevant records during surveys.
Compliance with S-Ox and related regulations must be a serious issue for corporate decision makers and IT departments. Penalties for violations range from loss of exchange lists to millions of dollars in fines and insults. Effectively handling spam should be a key part of the overall compliance strategy.
Orignal From: Spam filtering and compliance
No comments:
Post a Comment