You are here:About>Business & Finance>Business Security> Security Policies> Why Do You Need an Email Security Policy?
About.comBusiness Security
Newsletters & RSSEmail to a friendSubmit to Digg

Why Do You Need an Email Security Policy?

From Ryan Groom,
Your Guide to Business Security.
FREE Newsletter. Sign Up Now!

What is an email security policy?

An e-mail security policy is created to govern the proper usage of corporate e-mail. As many people have an e-mail account at work and at home, the lines of personal and corporate email tends to become blurred. I find that many people will use corporate e-mail just like they do the telephone; they use it for personal conversations that may not be of interest or could be a detriment to the corporation. Unlike the telephone, email is a communication medium that can be recorded forever. A simple personal email from a corporate account can cause embarrassment for a corporation or even inadvertent information disclosure.

Why do you need email security policy?

An email security policy is a necessary addition to any corporate infrastructure. The document details the usage of email so everyone in the corporation knows the boundaries of e-mail usage. If the employees have questions, they need to know how to refer to the policy. If the policy is unclear, the policy should detail who the employees should contact for clarity. If the same question is asked by many employees then the policy should be changed to clarify, which makes the policy more effective. If a policy is too hard to understand, then it is not much use.

Things That Should be in an Email Security Policy

The following are sections that should be included in an email security policy:

  • define prohibited use
  • if personal use is allowed, it needs to be defined
  • let employees know if their emails are reviewed and/or archived
  • what types of email should be kept and how long
  • when to encrypt email
  • consequences to violating email security policy

How to Make it Stick

  • Make it a part of the acceptable use policy.
  • Have the email security policy read and signed when the employment signs their employment agreement/
  • Have the email security policy read and signed when an email account is provisioned.

The following email security policy template is a good start to formulate your own email security policy. Read it over carefully and determine which sections apply to your business and determine any additional and unique sections you may need.

You will need Adobe Acrobat to view this template. Adobe Acrobat can be found at http://www.adobe.com/

Email Policy Template

 All Topics | Email Article | | |
Advertising Info | News & Events | Work at About | SiteMap | Reprints | HelpOur Story | Be a Guide
User Agreement | Ethics Policy | Patent Info. | Privacy Policy©2008 About, Inc., A part of The New York Times Company. All rights reserved.