AGAT

Categories
blog Education Microsoft Teams

Is Microsoft’s Information Barriers solution suitable for Education Tenants?

Recently, Microsoft has made its information barriers solution available to education tenants. In this article, we will cover some scenarios where educational organizations could implement information barriers, and also those aspects where Microsoft did not take steps to improve its features.

Table of contents:

  1. Using collaboration platforms in Education
  2. Information Barriers in Microsoft
  3. Policy-setting limitations and case scenarios for Education Tenants
  4. AGAT’s Solution

1- Using collaboration platforms in Education

As remote work continues to grow, tools that promote communication and collaboration from a distance have expanded too. The education sector has undergone a drastic technological transformation, especially after the pandemic, which pushed many institutions to incorporate online collaboration platforms into their daily activities. Even now, they still prove to be useful not only for distance learning but to complement traditional learning too: better connecting students, faculty, and staff. 

However, introducing technology into the classroom was not as straightforward. For the entire education sector, special needs arose that were not (and in many cases are still not) covered by the available software since it was developed for other purposes. All kinds of educational institutions, from K-12 to college, have faced challenges when it comes to shaping a plan to make collaboration safe for everyone, especially under-age kids.

One of the solutions many institutions started to implement were Information Barriers, a tool to set pertaining restrictions and manage communications between user groups. Information barriers were first ideated for the financial industry but now that the use of collaboration platforms has expanded, they proved to be useful in many scenarios.

information barriers for education tenants

2- Information Barriers in Microsoft

Previously, Microsoft’s Information Barriers were only available on E5 and E3 licenses, now all the Office 365 and Microsoft 365 education plans (A1, A3, and A5) will have access to them. Unfortunately, we can say that Microsoft hasn’t made improvements to its features before extending it to other licenses.

Microsoft’s Information Barriers can be used to set the next restrictions for users:

  • Adding a user to a team or channel
  • Prevent access to meetings
  • Prevent access to 1:1 chats and group chats
  • Prevent access to team or channel content

3- Policy-setting limitations and case scenarios for Education Tenants

As we see, Microsoft provides a solution that can prevent individuals or groups from communicating with each other or unauthorizing certain kinds of collaboration between them, but that’s about it. The problem with the options offered by Microsoft is that they lack flexibility, and many organizations do not want to impose a complete block between internal groups

For example, in a school environment, you might want to allow chat and meetings between teachers and students but, to prevent misconduct, block students from file sharing and screen sharing at the same time. 

Furthermore, to work, Microsoft’s Information barriers policies must be defined two-ways between groups, so they cannot communicate with each other at all. Given this, if you need to restrict students from reaching out privately to teachers but still allow teachers to start communications with students,  it wouldn’t be possible.

4- AGAT’s Solution

AGAT’s Ethical Wall information barriers solution for Microsoft Teams lets you have granular control over which kind of communications you block, for example chat, conferencing, file sharing, or screen sharing. Also, AGAT’s Ethical Wall allows you to set asymmetric policies, where you can choose to block users from reaching out only in one direction.

Finally, AGAT offers an easy-to-use interface to manage all your policies in one place, while Microsoft’s IBs require the use of PowerShell, a tool that can be too complex for non-technical administrators.

 To learn more about SphereShield’s Ethical Wall, contact us today.

Categories
blog DLP Ethical Wall

FINRA Compliance Requirements

Due to the COVID-19 pandemic, many companies had to restructure the way they worked almost overnight. Suddenly data that was protected by the organization’s regulations and contracts had to leave the company in order to work with it. That is the reason why FINRA extended all its compliance regulations to the internet space, establishing strict cloud governance standards and making cybersecurity a must.

Insider threats to enterprise data are a permanent cause of concern since they can impart a huge amount of destruction on a business, especially in the financial services sector. A simple mistype by an employee with privileged access can be just as damaging as a compromised employee looking to make a quick buck. Financial institutions face the second highest breach costs among targeted industries.

Table of contents

  1. What is FINRA?
  2. What does FINRA do?
  3. Rules regarding information barriers
    1. How to comply with FINRA information barriers requirements 
  4. Rules regarding data loss prevention (DLP)
    1. How to comply with FINRA DLP requirements
  5. Rules regarding archiving and data recovery
    1. How to comply with FINRA eDiscovery requirements

1- What is FINRA?

The Financial Industry Regulatory Authority (FINRA) is a private, nonprofit American corporation that acts as a self-regulatory organization (SRO). Its mission is to set forth rules and regulate stockbrokers, exchange markets and broker-dealer firms, keeping the U.S. markets safe and fair. FINRA is the successor to the National Association of Securities Dealers, Inc. (NASD) as well as the member regulation, enforcement, and arbitration operations of the New York Stock Exchange. 

The US government agency that acts as the ultimate regulator of the US securities industry, including FINRA, is the US Securities and Exchange Commission (SEC). Although FINRA is not a government organization, it does refer insider trading and fraud cases to the SEC, and if you fail to comply with FINRA rules, you may face disciplinary actions, including fines and penalties that are set to deter financial misconduct. 

2- What does FINRA do?

  • Oversees all securities licensing procedures and requirements for the United States.
  • It’s responsible for governing business between brokers, dealers, and the investing public.
  • Examines firms for compliance with FINRA and SEC rules. 
  • Performs all relevant disciplinary and record-keeping functions.
  • It encourages member firms to secure their financial data and execute transparent transactions. 
  • Delivers steps defining accurate cybersecurity goals.
  • It fosters transparency in the marketplace

Best practices Compliance FINRA

Is your company compliant? You must, among other things, make sure that digital data is immutable and discoverable and that the access and usage of data can be restricted, regulated and audited*. This is where AGAT’s SphereShield software can help.

3- Rules regarding Information Barriers

In a few words, financial institutions are subject to regulations that prevent employees in certain roles from communicating or collaborating with employees with other specific roles. Why is this? because there are conflicts of interest involved, and if they exchange sensitive information there can be severe consequences. 

A research analyst provides information to investors, they gather data around possible investment opportunities. Their increasing popularity expanded their influence on the price of securities: they give ratings that, if good, can make the price of an asset go way up. In parallel, a slight disfavorable change in their ratings can make prices drop. That’s why, to maintain a fair marketplace, research analysts cannot disclose ANY information they collected before an official public release.

The practice of information barriers has been expanded over recent decades to prevent those communications and risky information flows and to avoid insider trading, protecting investors, clients, and other key stakeholders from this wrongful conduct. FINRA Rules 2241 and 2242 require organizations to establish policies and implement information barriers between roles involved in banking services, sales, or trading from exchanging information and communicating with research analysts.

 – How to comply with FINRA information barriers requirements 

Agat’s SphereShield offers granular control over users/groups engaging in communications both within other areas of the company or with external organizations. It also includes independent control for different kinds of actions: instant messaging, audio, video, conferences, desktop sharing and file transfer. 

So, let’s say a user identified as a Research Analyst wants to communicate with someone from a restricted area: a well implemented information barrier will fully block that possibility.

4- Rules regarding data loss prevention (DLP)

Firms must put robust policies in place for employees to know which sensitive information they cannot disclose, and also monitor them for suspicious activities that  hint at possible misconducts. FINRA rules 3110/3013 explicitly mandate analyzing all electronic employee communications. 

Clearly, reading all emails and listening to all voice calls is just not possible, but there are technologies that can actively transcribe, analyze, and monitor communications flagging any suspicious behaviors or activities. As an extra step, there’s software that can assist a firm to turn surveillance from reactive monitoring (that means, addressing employees missteps after the fact) to a proactive rule creation approach. This allows for risks to be identified, managed, and mitigated before information breaches or other incidents occur.

– How to comply with FINRA DLP requirements 

AGAT’s DLP engine does real-time inspection of content, being capable of blocking or masking all data that is defined as sensitive before it reaches the cloud or is sent to external users. Firms can use it to prevent information leakages and insider trading offenses from happening, but it will also help them identify communication red flags  to make risk assessments and train personnel.

5- Rules regarding archiving and data recovery

Examining a company’s books and records to make sure they are up to date and accurate is a significant component of FINRA industry inspections. FINRA establishes in its rules that access to all the records they might need  to audit has to be accessible easily and promptly. 

FINRA rules 4511, 2210 and 2212 are the rules on storage and recordkeeping, stating that all organizations must preserve their records and books in compliance with SEC Rule 17a-4. This includes ensuring the easy location, access, and retrieval of any particular record for examination by the staff of the Commission at any time. This rule applies, and has specific notes to electronic storage, like accurately organizing and indexing all information. 

– How to comply with FINRA eDiscovery requirements

An eDiscovery search feature isn’t an ordinary content search tool. It provides legal and administrative capabilities, generally used to identify content (including content on hold) to be exported and presented as evidence as needed by regulatory authorities or legal counsels.

The eDiscovery solution from SphereShield allows for data to be immediately available to any regulatory organizations or commissions by giving advanced search capabilities to quickly retrieve and export data. This solution can also be integrated to other existing eDiscovery systems.

Categories
Announcement Education webex guides

Announcing Webex Teams Advanced Controls for Education

AGAT software introduces new Ethical Wall capabilities for Webex (Teams & Meetings) oriented to educational institutions with the label “Webex Teams Advanced Controls for Education”

By leveraging all the power of the Ethical Wall, SphereShield by AGAT is able to offer unique capabilities that suit requests from educational institutions using Webex Teams or MS Teams.

Having Webex Teams offering many degrees of freedom for collaboration and communication can be very useful sometimes, however, there are numerous cases where compliance, security and institutional protocols demand tighter controls and options.

Webex Teams Advanced Controls for Education was created following the requests of expert educators and IT professionals in the education industry. The main goals of this product are to adapt Webex Teams to the most rigorous security and code of conduct requirements and to improve the ongoing communications by providing a safe and reliable environment for both teachers and students.


The list of features explained for Webex Teams Advanced Controls for Education:

🔴Block students from communicating between grades
For example, a 7th grade student communicating with a 4th grade student.

🔴Make sure a teacher is present in every communication

Prevent student-only Spaces. Keep the organization protocols and safety.

🔴Automatically assign moderator role for the Teachers
Just as in the classroom. Avoid uncomfortable situations with students can remove a teacher 

🔴Control who can create Spaces
Allow only selected certain ActiveDirectory group members of the School faculty to create Spaces. Avoid undesired Spaces

🔴Block students from communicating with external users. Even block external users from adding a student to their Space
Restrict all communications outside of the school domain

🔴Control who can add participants to a space
Allow only teachers to add users to a space

🔴Lock down a Space that doesn’t have a teacher
No further communication will be allowed into existing spaces that are not aligned with new policies without losing the content

🔴 Automatically add global moderator to every space
Handle situations in which a space is left without a teacher or when a teacher has left the space. This will allow to add a replacement teacher

🔴Restrict troublemakers to communicate only with teachers.
Avoid risks of student-to-student communications with those of bad behaviour. Instead of removing them from Webex completely

🔴 Detect abusive language or use of sexual language
Inspect content using profanity filters

🔴 Detect adult / pornography / violent content in images

webex education policy 01 eaurle
A diagram of Webex Teams Advanced Control for Education Options


FAQ

Who is Webex Teams Advanced Controls for Education directed to?


Any educational institution from elementary schools to colleges, universities or online courses that use Webex Teams as their Unified Communications platform

How complicated is it to operate? Do you need a special administrator to run policies?


Webex Teams Advanced Controls for Education was designed for an easy operation, allowing less tech-savvy users to operate it with a minimal learning curve.
One or more administrators can be configured for setting policies.

What is the pricing of Webex Teams Advanced Controls for Education?


Webex Teams Advanced Controls for Education price varies by amount of users and other extra features required. On top of that, educational institutions receive special education pricing.

Is there a Demo?

Contact our sales team today and they will be able to let you interact with a Free Demo

Is this service available for Microsoft Teams and other platforms?


By the time of this announcement, SphereShield Ethical Wall for Microsoft Teams will be counting with the same features that Webex Teams Advanced Controls for Education has applied to Microsoft Teams.
We are working on integrating these new capabilities into Slack and Zoom and will announce when they are live.

 

 

AGAT Software is a certified solution provider for Cisco Webex Teams and Meetings

To learn about SphereShield Ethical Wall for Webex Teams and meetings click here