Outlook Security

  • Thread starter Thread starter Sherman H.
  • Start date Start date
S

Sherman H.

I am reviewing security settings of our Outlook servers for my company and
would like to know from you what would be the vulnerable areas/items I
should look into. Any comments are appreciated.

I know blocking download executables and other attachments are vulnerable to
backdoor Trojans.
 
1) A antivirus product that integrates well into your internet mail gateway
setup. For example, if I was running Microsoft Exchange, I would want an
Exchange aware antivirus product that can do ESE and/or VAPI 2.x. (ESE for
Exchange 5.5 while VAPI 2.x appears to be working very well under Exchange
2003.) Product should allow you to disable notifications to
sender/recipient that something was purged. Today's viruses that spoof
sender information make this a needed feature.

Don't forget that this product should scan all inbound and outbound
messages. In the unfortunate event that corporate does take a hit, it
shouldn't be using the servers to spread. Remember the rest of the world
doesn't need to know what just happened. ;)

2) A antispam product that integrates well into your internet mail gateway
setup

3) Make sure that the server is configured not to relay

4) Server should have the option of disabling NDRs.

5) If possible, do not allow users to check their personal or non-corporate
mail servers. Corporate firewall should disallow IMAP, POP3, and SMTP for
the corporate desktop. If corporate went to the trouble of providing e-mail
services to its staff, then make sure they understand the corporate e-mail
policy.
 
What is ESE and VAPI?
neo said:
1) A antivirus product that integrates well into your internet mail gateway
setup. For example, if I was running Microsoft Exchange, I would want an
Exchange aware antivirus product that can do ESE and/or VAPI 2.x. (ESE for
Exchange 5.5 while VAPI 2.x appears to be working very well under Exchange
2003.) Product should allow you to disable notifications to
sender/recipient that something was purged. Today's viruses that spoof
sender information make this a needed feature.

Don't forget that this product should scan all inbound and outbound
messages. In the unfortunate event that corporate does take a hit, it
shouldn't be using the servers to spread. Remember the rest of the world
doesn't need to know what just happened. ;)

2) A antispam product that integrates well into your internet mail gateway
setup

3) Make sure that the server is configured not to relay

4) Server should have the option of disabling NDRs.

5) If possible, do not allow users to check their personal or non-corporate
mail servers. Corporate firewall should disallow IMAP, POP3, and SMTP for
the corporate desktop. If corporate went to the trouble of providing e-mail
services to its staff, then make sure they understand the corporate e-mail
policy.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Back
Top