Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


February 14, 2008

Avoiding Rookie Legal Mistakes in Your Messaging Environment

RSS
Subscribe to Windows IT Pro | See More Exchange Server and Outlook Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

Last week, I wrote about two recent situations where major companies suffered from entirely avoidable email-related problems ("Rookie Legal Mistakes Hurt Large Companies," February 7, 2008). In one case, Qualcomm lost a major patent dispute, and six of its outside attorneys are now staring down the barrel of possible disbarment. In the other case, an attorney working for Eli Lilly & Company accidentally sent a highly confidential document to a New York Times reporter. How could these mishaps have been prevented?

Let's start with Qualcomm, or, more precisely, with two of its outside law firms. The court found that the attorneys involved failed to produce relevant email messages and that they did so on purpose. The immediate fix for this type of problem would seem to be "don't hire dishonest attorneys"—but that presupposes that you can tell which ones are dishonest in the first place!

Consider what might have happened if Qualcomm had a more effective system for handling electronic disclosure requests. For example, if the company had been performing regular audits of its archiving system to see how many results were produced for important terms, there might have been some warning that the results offered to the court were incorrect or incomplete. It's not clear whether Qualcomm performed the discovery operation inhouse or outsourced it, but it would seem that a more effective internal compliance operation might have been able to prevent the problem in the first place. I'll certainly be advising my clients who use outside law firms for compliance and discovery issues to ensure that their contracts for these services include hefty penalties for the kinds of shenanigans that Qualcomm's attorneys apparently pulled.

The Eli Lilly case is a bit more complex. Ignore the fact that the accidental disclosure was made by an attorney working for Lilly's outside law firm. Although it makes for great lawyer jokes, the fact is that this sort of accidental disclosure could easily have happened to many other people in the organization—though you have to have pretty bad luck to mistakenly send a critical document to a reporter for one of the world's best-known news organizations! My first thought when I read about this was that Lilly could benefit from using information rights management software such as Windows Rights Management Services (RMS) or Adobe LiveCycle to apply technical protection to their messages. If they'd done so, the protected message still would have gone to the reporter, but he would have been unable to open it. I think such an approach is probably best, but there are a few other "what if" scenarios that might have helped prevent this problem:

  • What if the law firm had deployed message classification tags and an Exchange Server 2007 transport rule? With this combination, their Hub Transport servers could automatically reject messages tagged as privileged but sent to domains other than those of the specific customer.
  • What if the law firm had used email policy control software to scan outbound messages for customer names or other sensitive details, quarantining matching messages for human inspection?
  • What if the sender had taken the time to double-check the recipient address on the message before sending it?
None of these scenarios, of course, solve the problem that's already occurred, but all of them are worthy of consideration because they highlight the fact that there's more than one way to limit inappropriate email disclosure. I'm a big fan of RMS because it helps you apply fairly strong policy controls that greatly reduce the impact of mistakes such as those in these two cases. A malicious user can still disclose protected information with a camera, a phone call, or pad and paper, but RMS makes it harder to accidentally or unknowingly spill the beans. However, message classification and transport rules are already included in Exchange 2007, so that's probably the lowest-cost way to start adding this kind of policy protection to your environment.

End of Article



Reader Comments

You must log on before posting a comment.

If you don't have a username & password, please register now.




Top Viewed ArticlesView all articles
The Memory-Optimization Hoax

Don't believe the hype. At best, RAM optimizers have no effect. At worst, they seriously degrade performance. ...

Command Prompt Tricks

One reader shares his tip for setting up the command prompt to reflect a remote path. ...

WinInfo Short Takes: Week of November 24, 2008

An often irreverent look at some of the week's other news, including a Vista Capable dismissal request, Zune price reductions, Morrow musings, Novell and Microsoft sitting in a tree ... two years later, Yahoo!, IE 6 on Windows Mobile, and so much more ...


Related Articles Rookie Legal Mistakes Hurt Large Companies

Well, I Disclaim!

Messaging Records Management

Exchange 2007 Transport Rules

Exchange Server and Outlook Whitepapers Protecting (You and) Your Data with Exchange Server 2007

StoreVault SnapManagers for Microsoft Exchange and SQL Server

Related Events The Myths & Truths of Email Management with SharePoint

Top 10 Email Security Challenges and Solutions

Mastering Exchange 2007 Server Management – May 29, 2008 (11:00 AM EST)

Check out our list of Free Email Newsletters!

Exchange Server and Outlook eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

The Expert's Guide for Exchange 2003: Preparing for, Moving to, and Supporting Exchange Server 2003

Related Exchange Server and Outlook Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.

Exchange & Outlook UPDATE eNewsletter
News, strategies, products, and developments in Exchange Server and Outlook messaging.

Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound ITTV
IT Library Technology Resource Directory Connected Home Windows Excavator Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2008 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing