First off, you're going to need to take an inventory of where your email is used and stored (Outlook, the web,...
personal phones, etc.). Next you need to determine your legal obligations related to email security and retention. How do the federal privacy and security regulations such as HIPAA affect your business? What about state breach notification laws?
You also need to decide how critical any/all of the emails are to your business - not only for future internal reference but also e-discovery. Deciding which emails are important will help to classify the different types of email. If that's too much of a challenge, at least consider separating out the emails that have attachments, since that's where a lot of sensitive information tends to be, and specific users or groups of users. This ensures that their email is handled and stored properly. As for instant messaging and social media messaging, if they're key to the business, you may want to consider bringing them into the scope as well.
This exercise is going to require the input from a lot of different people. You should never assume anything and don't just download someone else's data backup and retention policy and procedures off the Internet and believe that's going to be enough. At the very least, get your lawyer involved as he/she is going to be making a lot of key decisions related to this.
Dig Deeper on Disaster Recovery Planning-Management
Related Q&A from Kevin Beaver
Knowing how to test for security flaws is vital, but it's a complicated and changing field. Expert Kevin Beaver offers security testing basics.continue reading
How do self-healing networks function? Expert Kevin Beaver looks at the benefits such a network has to offer, as well as the key concepts ...continue reading
While there are numerous security benefits to a DNSSEC implementation, there are drawbacks as well. Expert Kevin Beaver explains.continue reading
Have a question for an expert?
Please add a title for your question
Get answers from a TechTarget expert on whatever's puzzling you.