IM Instant Messaging Security

This chapter has been contributed by Terry L. Dalby, CISM, CISSP, who has over 30 years' experience in network operations, performance management, and security operations specifically in the telecommunications industry and with large service providers in the United States and Europe. He has been responsible for the design, installation, and operations of extremely large heterogeneous networks, including traditional IP elements as well as fiber and RF systems that provided backbone and distribution for converged voice, video, and data traffic. His publishing credits include Computer Interfacing: A Practical Approach to Data Acquisition and Control, as well as multiple magazine articles relating to security management. He is currently a Principal Information Security Engineer at Qwest Communications.
IM isn't just another question facing businesses today, it is arguably the question. As stated previously, it isn't whether or not to employ IM in the enterprise but rather, how do we control it? IM offers businesses significant benefits in enhanced workgroup communications that are easier and quicker in many cases than the e-mail and voice alternatives, but IM brings risk.
Recent studies have found that more than 90 percent of companies surveyed have IM traffic in their networks while as few as 18 percent of Fortune 500 companies have officially deployed IM [1]. Most of the adopters are in the communications and high-tech sectors. This disparity between ad hoc use and official use is typical across the board and makes the formal acceptance of IM a difficult issue to...