Table of Contents

Search

  1. Preface
  2. Informatica Managed File Transfer Welcome Overview
  3. Dashboard
  4. Resources
  5. Workflows
  6. Task Reference
  7. Services Overview
  8. Users
  9. Logs and Reports
  10. Encryption
  11. System
  12. Appendix
  13. Glossary Terms

Choosing the Right Encryption Method

Choosing the Right Encryption Method

There are several factors to consider when choosing the encryption standards to implement.  The flexibility in
Managed File Transfer
allows you to choose the encryption standard for each individual transfer.  For instance, you may want to use a simple encryption standard (such as ZIP) when exchanging not-so-sensitive data with a customer, whereas choose a strong encryption standard (such as OpenPGP) when exchanging highly-sensitive data.
The following questions should be asked before choosing the encryption standard to use:
  1. How sensitive is the data being exchanged?
  2. How will the data be transported (for example, FTP, Email, HTTP)?
  3. Are large files being exchanged (which should be compressed)? 
  4. Should the files be encrypted (before transmission) or should the connection be encrypted?
  5. What encryption standards does your trading partner support?
    A trading partner may dictate the encryption standards which they support.  For instance, many banking institutions require that their customers encrypt files using the OpenPGP encryption standard. 
    Listed below are several sample scenarios and the recommended encryption standard to use.
Scenario 1
You need to send your price list file to your customers over email.  You want to make it simple for the customers to open the file.  The price list information is not extremely sensitive, but you would like to at least password-protect it. 
Scenario 2
You need to send your payroll direct deposit information to the bank.  This is considered as highly sensitive information.  The bank wants you to send this information over a standard FTP connection. 
Recommendation:  OpenPGP 
Scenario 3
Your trading partner wants to exchange information with you over a secure FTP connection.   This trading partner wants to authenticate your company with a password or public key.
Recommendation:  SFTP (SSH File Transfer Protocol)  
Scenario 4
Your trading partner wants to exchange information with you over a secure FTP connection.  This trading partner wants to authenticate your company with a signed certificate.
Recommendation:  FTPS (FTP over SSL) 
Scenario 5
You need to send purchase orders to your vendors, which you consider as fairly sensitive.  The files can be rather large in size and should be compressed.  The purchase orders could be sent over standard FTP connections or via Email.
Recommendation:  ZIP (with AES encryption) or OpenPGP 
Scenario 6
You need to send EDI information securely to a trading partner and you need confirmation that they received the exact document(s) you sent them.
Scenario 7
You need to send sensitive information in the message body of an email.
Recommendation: Secure Email

0 COMMENTS

We’d like to hear from you!