For Questions Call: BANGALORE: +91-080-43331600, MUMBAI: +91 22 4070-0290
White Papers|Downloads|Search

Policy Authority for Unified Communications Home > Policy Authority for Unified Communications > IM Compliance - Quest Policy Authority for UC

Print Page

Request More Info Email Page
Overview
Features and Benefits
Release Information
Document Library
Webcasts and Events
Trial Download
Appliance
Compliance
Preserve
Security
Platforms

Product Of The Year 2008 - Unified Communications
Quest’s Response to the FSA Data Security Report

IM Compliance

Information Control, Retention and Review, and Privacy Protection and Security

Real-time communications – including email, IM and mobile messaging – are subject to an increasing number of industry and government regulations. Demonstrating compliance with these rules and standards presents a key challenge for today's organization. And the consequences are clear: Out-of-control real-time communications can lead to fines for non-compliance, lost reputation, lost intellectual property, and further liability to your organization.

IT organizations need a solution to enforce policies and controls – based on end users’ corporate directory attributes – to regulate user activity, protect against data loss, and to archive IM and mobile messaging for compliance purposes.

Quest Policy Authority for UC helps organizations address two primary areas of IM and mobile messaging compliance: Information Control, Retention and Review and Privacy Protection and Security. Read below to find out how.

Information Control, Retention and Review

Organizations are required to control who can IM with whom (such as enforcing ethical walls), log and archive all IM, and to systematically review messages.


Regulation
Industry
Requirement
How Quest Policy Authority Helps
SEC 17a-3 and 17a4Financial ServicesArchive and review of electronic communicationsCheck!  Archiving all IM conversations
Check!  Real-time monitoring of flagged messages
Check!  Flexible web-based search and retrieval
Check!  Multiple user roles for systematic audit of messages
Check!  Annotation and email escalation of flagged or blocked messages
FDICMember Banks and Financial InstitutionsRetention and review of all electronic communicationsCheck!  Archiving all IM conversations
Check!  Real-time monitoring of flagged messages
Check!  Annotation and email escalation of flagged or blocked messages
Check!  Flexible web-based search and retrieval
Check!  Multiple user roles for systematic audit of messages
Check!  Annotation and email escalation of flagged or blocked messages
NASD 3010 and 3110Financial ServicesRetention and review policies for electronic communications

Originals of all communications received and copies of all communications sent by such member, broker or dealer
 
Broker-dealers should prohibit communications from home computers and third party platforms unless such communications can be retained and reviewed
Check!  Archiving all IM conversations
Check!  Real-time monitoring of flagged messages
Check!  Annotation and email escalation of flagged or blocked messages
Check!  Flexible web-based search and retrieval
Check!  Multiple user roles for systematic audit of messages
Check!  Archive SMS text messaging
Check!  Archive PIN-to-PIN text messaging
Check!  Log inbound and outbound phone call numbers and call lengths
NASD 2711Financial ServicesSeparation of broker-dealers from investment analystsCheck!  Flexible access control to enforce ethical walls
Check!  Annotation and email escalation of flagged or blocked messages
NYSE Rule 440Financial ServicesRetention of all electronic communicationsCheck!  Archiving all IM conversations
Check!  Flexible web-based search and retrieval
FINRA #07-59Financial ServicesText messaging is a communications mode that is considered 'electronic communication' and must be retained.Check!  Archive SMS text messaging
Check!  Archive PIN-to-PIN text messaging
Check!  Log inbound and outbound phone call numbers and call lengths
FERC/NERCEnergyRetention and review of all electronic communicationsCheck!  Archiving all IM conversations
Check!  Real-time monitoring of flagged messages
Check!  Annotation and email escalation of flagged or blocked messages
Check!  Flexible web-based search and retrieval
Check!  Multiple user roles for systematic audit of messages
Check!  Annotation and email escalation of flagged or blocked messages
Sarbanes-OxleyPublicly-tradedAvailability of historical communications for audits and ethical walls for analystsCheck!  Archiving all IM conversations
Check!  Flexible access control to enforce ethical walls
Check!  Flexible web-based search and retrieval
Check!  Multiple user roles for systematic audit of messages
Check!  Annotation and email escalation of flagged or blocked messages
Freedom of Information ActFederal Government Agencies and ContractorsControl and retention of all recordsCheck!  Archiving all IM conversations
Check!  Flexible web-based search and retrieval
Check!  Annotation and email escalation of flagged or blocked messages
21CFR Part 11Life Sciences and PharmaceuticalsRetention and audit of "e-records"Check!  Archiving all IM conversations
Check!  Flexible web-based search and retrieval
Check!  Multiple user roles for systematic audit of messages
Check!  Annotation and email escalation of flagged or blocked messages
5015.2STDDepartment of DefenseRetention and audit of messagesCheck!  Archiving all IM conversations
Check!  Flexible web-based search and retrieval
Check!  Multiple user roles for systematic audit of messages
Check!  Annotation and email escalation of flagged or blocked messages
Regulation FDPublicly-tradedControl over external communicationsCheck!  Archiving all IM conversations
Check!  Flexible web-based search and retrieval
Check!  Annotation and email escalation of flagged or blocked messages
Amended Federal Rules of Civil ProcedureAll organizations that may be involved in litigation in a Federal courtRetention, disclosure, and production of electronic messages (including IM and chat)Check!  Archiving all IM conversations
Check!  Flexible web-based search and retrieval
Check!  Multiple user roles for systematic audit of messages
Check!  Annotation and email escalation of flagged or blocked messages
FSA Policy Statement 2008 A1.64-A1.71Financial Services (UK)Archive and review of electronic communicationsCheck!  Archiving all IM conversations using tamper proof mechanism
Check!  Archiving all File Transfers
Check!  Binary logging or message formatting, color, style
Check!  Multiparty Chat logging including join/leave timestamps
Check!  Flexible web-based search and retrieval
Check!  Multiple user roles for systematic audit of messages
Check!  Annotation and email escalation of flagged or blocked messages
FSA Policy Statement 2008 A1.70-A1.71Financial Services (UK)Enforce usage policies for IMCheck!  Flexible access control to enforce ethical walls
Check!  Automatic display of legal audit disclaimers to all parties
Check!  Restrict inter-organization communication
Check!  Ensure all IM communication are directed through authorized channels
Privacy Protection and Security

Organizations are also required to protect sensitive information (such as consumer financial or health-related data) when using IM or other forms of real-time communications.

Regulation
Industry
Requirement
How Quest Policy Authority Helps
HIPAAHealthcare-relatedProtection of all patient health informationCheck!  Flexible keyword and pattern (such as SSN) filtering
Check!  Granular access control by user, group and domain
Check!  File transfer control by user and file type
Gramm-Leach-Bliley ActAll industriesProtection of customer financial non-public private information (NPPI)Check!  Flexible keyword and pattern (such as credit card number) filtering
Check!  Granular access control by user, group and domain
Check!  File transfer control by user and file type
California SB 1386All California industriesProtection of personal informationCheck!  Flexible keyword and pattern (such as SSN) filtering
Check!  Granular access control by user, group and domain
Check!  File transfer control by user and file type
EU Data Protection Act (EUDP)All California industriesProtection of personal informationCheck!  Flexible keyword and pattern filtering
Check!  Granular access control by user, group and domain
Check!  File transfer control by user and file type
PIPEDAAll Canadian industriesProtection of personal informationCheck!  Flexible keyword and pattern filtering
Check!  Granular access control by user, group and domain
Check!  File transfer control by user and file type


White Paper: Compliance and Data Loss Prevention in Unified Communications SolutionsCase Study: Read how customers are benefiting from Policy AuthorityWhite Paper: Best Practices for IM Management
 
 






        © Quest Software, Inc. All rights