Protect Email Attachments

I'm looking to distribute via exchange email a file companywide, but want to protect that attached file from being downloaded, renamed, printed, etc.

Anyone have any thoughts on this?
supportservicesAsked:
Who is Participating?

Improve company productivity with a Business Account.Sign Up

x
 
JohnConnect With a Mentor Business Consultant (Owner)Commented:
If you look at Word, there is no foolproof way to prevent a document from being printed once it is distributed and out of your hands.

http://word.tips.net/T001583_Preventing_Printing.html

What you might be able to do is implement Document Rights Management (which is an undertaking)

https://support.office.com/en-us/article/Information-Rights-Management-in-Office-2010-c7a70797-6b1e-493f-acf7-92a39b85e30c?ui=en-US&rs=en-US&ad=US

This might assist you. The results should cover Excel as well.

For Adobe, you can protect a file against being changed or even combined with another file. But preventing from printing is also difficult.
0
 
supportservicesAuthor Commented:
We are trying to protect a scanned image in pdf format. Although we can protect the document, we haven't figured out a way to prevent anyone from downloading, renaming and forwarding the document.
0
 
JohnBusiness Consultant (Owner)Commented:
Go into Adobe, open the file, Edit Preferences, Security, Adobe Live Cycle Rights Management Servers.

I think you can do what you want there.
0
 
Jessie Gill, CISSPTechnical ArchitectCommented:
What are you trying to achieve?  It looks like to me, that you want users to see the file but have no rights to do anything else.  There are 2 issues, one is first with delivery and the second is once the user has the file.  The delivery can be handled by certificates and encryption.   The second problem is once a user can see the file/information they can use other tools to capture the information like screen shots etc.  

For delivery
If you want confidentiality, so only intended recipients can open the file – then encrypt the file.  You will need to have user certificates enabled, PGP or s/mime.  You would encrypt the file using the recipient’s public key.  The recipient would then use their private key to un-encrypt it.
If you want to ensure the file is not tampered when its gets to the recipient then HASH the file also.
If you want non-repudiation then encrypt the file with the sender’s private key.

Once on the machine
Now that the user has the file what can you do to protect it.  Like John said there are some settings you can use within Adobe.  If you want to stop the file from leaving the organization you could setup an exchange transport rule, but that is not fool proof.  But once the file is on the user’s machine they usually have some way of getting the information like a screen shot or something.  
There is no 100 percent way to stop the information that you will be sending out not to be resent again in one form or another.  The only real protection is End user security awareness, users understanding your security policies, and only sending information to people that need to know.  But ultimately it will be the end user responsibility, to not do inappropriate actions with the file once they have it.
0
 
Rich RumbleSecurity SamuraiCommented:
Computers are copying machines, if you give me an image, I  can print it, if I can view it I've already copied it, technically. They can take a screen-shot, then can use save-as etc... If you want to distribute something that you need physical control over, then make it physical, print it out yourself, keep a count of the copies, expect them all to be returned.
PrintScreen is the easiest bypass, and most of my user's are aware of it. I've used FileOpen, Microsofts DRM, IronPort and tried everything you can think of. You can make it hard, but it's not impossible. FileOpen has the best DRM I've used, and makes it the most difficult to bypass, but it's no 100%. It can't prevent the ability to display on other machines, but if they read their email from more than one machine, you cannot stop that from being viewed. They might not be able to fwd it where it's readable, but they can view it elsewhere. It's an impossible problem to solve, but it can be made more difficult.
-rich
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.