Blog
Non-Employee Risk Management Security Updates: DMARC, TLS, DNSSEC
Author
jeff_lakey
SailPoint
During this quarter, Non-Employee Risk Management will be enabling several changes to improve the overall security of the application. These changes should be largely invisible to end users, and for most customers will not require any actions to be taken.
Non-Employee Risk Management will now employ a DMARC policy to emails generated with a nonemployee.com address.
- This ensures that all mail sent from Non-Employee Risk Management originated and is signed by a mail server authorized to be the mail sender.
- If your client receives an email that purports to be from a nonemployee.com address, but it does not have the correct signature or the correct sending IP address, that email will be quarantined.
- In Q3, we anticipate updating the policy to reject, rather than quarantine the unauthenticated emails
- FAQ on DMARC: https://dmarc.org/wiki/FAQ
All outbound HTTPS communication from Non-Employee Risk Management will soon require FIPS 140-3 certified encryption and hash algorithms.
- Please ensure that all your HTTP server targets and custom SMTP servers support TLS 1.3 (recommended).
- If using TLS 1.2, please ensure that it is up to date with Extended Master Secret support (EMS), and current Secure Renegotiation.
- More on FIPS 140-3 requirements for cryptographic modules: https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-3.pdf
Non-Employee Risk Management will soon support DNSSEC, a security layer for DNS, for Nonemployee.com and other production domains.
- For users running most modern operating systems, this should not cause any problems.
- If your organization does not require DNSSEC, your users will still be able to access nonemployee.com domains as normal.
- If your organization requires DNSSEC, please ensure that your DNS resolvers support DNSSEC as well (this should already be the case if you require DNSSEC).
- DNSSEC FAQ: https://www.icann.org/en/system/files/files/dnssec-faqs-23jun10-en.pdf