Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

Anchor
_Hlk5609214
_Hlk5609214
Anchor
_GoBack
_GoBack
Sending Encrypted Emails from Outlook with Office 365

PURPOSE

To allow users to securely send email messages and attachments to external users without installing PGP Client Software.

SCOPE

All NYSERDA Users

RESPONSIBILITIES

  1. IT Operations Systems Administration is responsible for User Account and Mailbox Administration
  2. All users are responsible for knowing the Data Classification for any information and/or files being shared both within and outside of NYSERDA and assuring this information is properly secured in accordance with that classification.

...

*Contact Data Governance for more details on Data Classification

PROCEDURES


  1. Sending Secure, Encrypted Email from Outlook has been made very easy for NYSERDA users now on the Office 365 email platform. To send an encrypted email to an external user you simply need to add the appropriate wording to the Subject of the message.
    1. Create new message in Microsoft Outlook and add the recipients like usual.
    2. Enter the following to the beginning of your "Subject" #encrypt

...

                           Please contact me if you have any questions or issues accessing the encrypted email.  We appreciate your commitment to protecting sensitive information.


DATA LOSS PROTECTION (DLP)

Data Loss Protection (DLP) to prevent unprotected sensitive information in outgoing email.  NYSERDA’s Data Governance Council have agreed to enforce the least disruptive action known as the DLP encryption template.  This encryption template is effective immediately.

...

Receiving the email works the same as utilizing #encrypt referenced above.


PASSWORD PROTECTING FILES

  • Information may be intercepted in motion when sending an email to an external stakeholder so attachments must be converted to an Adobe or MS Word or Excel .xlsx password protected file for Confidential-Internal, Confidential-Private or Confidential-Restricted data before sending an encrypted email to an external stakeholder or emailing a State entity within the ITS domain.

...