Feeds

The politics of email in the workplace

Mixing business with pleasure

Intelligent flash storage arrays

A second approach is to permit personal use of corporate or governmental email systems, with restrictions (no abusive or inappropriate use) and possibly a mandatory notation on personal email - "this is not an official government email". This is the general approach taken by the US Government. However, depending upon the judgment of individual employees to determine whether an email is "personal" or "official" is inexact at best. Content filtering software may help here, but it is not perfect.

A third approach is to make it clear that corporate or government email is exclusively for corporate or government work, and to enforce such policies (or try to) with white lists, content filtering, spot checks (supervisory monitoring) and actual enforcement, but couple this policy with permission to make limited and non-offensive use of personal email systems (e.g. POP3 mail) with appropriate safeguards (anti-viral, anti-spam, etc). Now remember, such webmail may effectively bypass some corporate security policies, and may be inappropriate in some regulatory environments - such as broker-dealers who have to monitor all communications to potential investors. And this again relies on the individual user to decide that a particular email is "personal" or "business".

Issues related to 'personal' email on company systems

There are many issues that relate to the use of non-business email through business provided - or reimbursed - IT infrastructures. First, may (or must) the employer monitor the contents of such "personal" email systems? May they "intercept" things like the user's userid and password on a personal system, and if so, what can they do with this information? If an employer reimburses an employee for all or part of their home internet connection (or telephone or cell phone service) does that give them the right to monitor the contents of communications on these systems? The answers here are not clear, and may depend on the intersection between privacy law, federal or state wiretap laws, electronic surveillance laws, and actual and stated policies on monitoring.

Who "owns" such "personal" email? Who makes decisions about retaining it? Deleting it? Producing it? The problem is multiplied when we consider telecommuting, use of personal hardware, access to personal email through personal networks for which the company may reimburse the employee. Further complicating the matter is the fact that companies provide employees with other devices from which they may access their corporate and personal email, and these devices may or may not have the same controls on their use.

Smartphones, BlackBerries and other devices have the ability to access both personal and business communications. Who "owns" these devices, and who has a right to access the communications contained in them or transmitted through them? Will we require our employees to maintain two separate communications networks - a personal cell phone and a business one? Many companies do just that - with the result that staff members' attire begins to resemble the batman utility belt - PDA, BlackBerry, cell phone, etc.

The document production problem

The problem of document retention and destruction is complicated by the use of personal communications on corporate or government networks. As a general rule, in response to a subpoena, document demand, court order, preservation request or other legal process or obligation, a company or agency must preserve or produce any "documents" within their "possession, custody or control". But how does this relate to personal emails - particularly on those sent outside of the company email system?

The merger of personal and company business creates privacy problems for employees and production problems for employers. If a company is required to preserve or produce, for example all documents related to "the Jones matter" would that include a personal email sent by an employee on a personal email system from a home PC? Probably not, as that document is not in the "possession, custody or control" of the company. But if the employee connected to the corporate VPN when he or she sends the personal email, the situation changes. What would the company's responsibility be for, for example, an employee's diary sitting on a company desk? Does this need to be preserved and produced? "Reply hazy, try again later".

Secure remote control for conventional and virtual desktops

Next page: The Karl Rove issue

More from The Register

next story
MI6 oversight report on Lee Rigby murder: US web giants offer 'safe haven for TERRORISM'
PM urged to 'prioritise issue' after Facebook hindsight find
I'll be back (and forward): Hollywood's time travel tribulations
Quick, call the Time Cops to sort out this paradox!
Assange™ slumps back on Ecuador's sofa after detention appeal binned
Swedish court rules there's 'great risk' WikiLeaker will dodge prosecution
NSA mass spying reform KILLED by US Senators
Democrats needed just TWO more votes to keep alive bill reining in some surveillance
prev story

Whitepapers

Driving business with continuous operational intelligence
Introducing an innovative approach offered by ExtraHop for producing continuous operational intelligence.
The total economic impact of Druva inSync
Examining the ROI enterprises may realize by implementing inSync, as they look to improve backup and recovery of endpoint data in a cost-effective manner.
Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Simplify SSL certificate management across the enterprise
Simple steps to take control of SSL across the enterprise, and recommendations for a management platform for full visibility and single-point of control for these Certificates.