Educause Security Discussion mailing list archives

Re: Employees forwarding their email offsite


From: Karen Brown <ksbrown () MIRACOSTA EDU>
Date: Tue, 26 May 2020 16:25:46 +0000

Hi Jonathan,

1.    Yes but only for employees.

2.    We no longer permit auto forwarding. I don't know that we have a "policy," but believe we are working towards it. 
We educate users to not forward FERPA, PII etc and to use an encrypted service to which we subscribe  if the data MUST 
be forwarded. We monitor outbound mail for DLP and send it to a quarantine, educate the user, and send encryption 
directions.

3.    Yes. We are blocking via Office 365.

A role assignment policy blocks auto forwarding rules from functioning. We do not assign the role to students.

For Outlook web, we use an outlook web policy that removes the forward option entirely.

From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU> On Behalf Of Kimmitt, Jonathan
Sent: Tuesday, May 26, 2020 9:12 AM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: [SECURITY] Employees forwarding their email offsite

Hi all,

  After an issue has come up, we are looking at a way to prevent employee's (but not students) from auto-forwarding 
their university email to personal email accounts.

I was curious to what other Universities were doing.

1.       Are you blocking auto forwarding?
2.       Do you have a university policy on what can and can't be sent?
3.       Is anybody doing this in an office365?

Thank for anything you can share!

-Jonathan

~
Jonathan Kimmitt
CISSP, PCIP, CEH, CIPM, CDPSE
GPEN, CIPT, CIPP/E, GSNA
Chief Information Security Officer
Information Technology
The University of Tulsa
918.631.2743


**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://www.educause.edu/community<https://urldefense.proofpoint.com/v2/url?u=https-3A__www.educause.edu_community&d=DwMFAg&c=bxXB6XgK3xQjNA1pniRjug&r=a9iWaHMXFWL9c1TccEfCGeoibkJP4gSWup_UiQkYdHQ&m=8oYdI0PjcTmHRcl031HnAzpVWWV8LdMZCNWcBps2pRo&s=j-P03tpJYUJ5tFZLNJqeAej3_EaDS5d3j8-JjZnFLUY&e=>

**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at https://www.educause.edu/community

Current thread: