Rights of Passage
Enterprise rights management software ensures that sensitive documents and e-mail can be circulated and don't end up in the wrong hands.
Computerworld - When Corning Inc. began selling products for military and aerospace use, the optical-fiber and cabling product manufacturer needed a way to show that it was following export controls and handling sensitive documents properly. "The government regulations are very explicit," says James Scott, director of knowledge and information management. To meet those requirements, the Corning, N.Y.-based company deployed enterprise rights management (ERM) software from Liquid Machines Inc.
Corning's research and development staff uses the software to encrypt critical documents and apply rules that determine not just who has access to the files but also whether they can print, copy or forward them to others. The system also establishes a chain of custody, providing an audit trail of who accessed a document when and what they did with it. "We can put our hands on our hearts and say we know we are compliant," Scott says.
Government contractors such as Corning aren't the only organizations thinking about document security these days. Recent high-profile data thefts and government regulations covering everything from financial disclosure to customer privacy have businesses worrying about where sensitive e-mail is going. IT organizations are struggling to control both dissemination of and access to corporate data contained in e-mail messages, Word documents or other electronic document formats. Leaked customer data or an untimely release of financial information can lead to public embarrassments as well as legal fines.
But Corning, like many other organizations with large R&D investments, has another concern: protecting documents pertaining to intellectual property that it's developing. "Many companies are very lax in their understanding and use of [ERM] as a way to protect their intellectual property," Scott says.
ERM Inside
Like digital rights management software, ERM products lock documents by encrypting them. But while DRM focuses on the consumer, ERM systems are designed to support document security policies both within and between businesses and to provide an audit trail.
In an ERM system, a policy server stores encryption keys, authorizes user access to documents and maintains policy templates that store rules that dictate what users in different roles can do with different classes of documents. Users then apply those policies to documents as they create them. Most products require users to run agent software or plug-ins designed to work with specific applications, such as Microsoft Word or Internet Explorer. Others, such as Microsoft Corp.'s Rights Management Services (RMS), require that applications be modified to natively support the ERM system's application programming interfaces (API). Most also require an identity management infrastructure.
"If you don't have an enterprise directory, it will be more challenging," says Trent Henry, an analyst at Burton Group in Midvale, Utah.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
- Streamline Compliance and Increase ROI
- Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will...
- X-Ray of the PCI Process-4 Proactive Steps
- This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into... All Gov't Legislation/Regulation White Papers
- Optimizing Networks for the Cloud
- Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
- Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
- Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
- Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
- Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
- Customer Spotlight: How IPC The Hospitalist Company Implemented Oracle on VMware
- Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn...
- Virtualize Business-Critical Applications with Confidence
- Virtualizing business-critical applications has become a key focus for organizations as they move along their virtualization journey. With the launch of VMware vSphere®... All Gov't Legislation/Regulation Webcasts