Security at scale: What’s new for enterprises

More security control and greater compliance with Slack Enterprise Key Management, expanded HIPAA capabilities and new native mobile security features

Slack 팀이 작성2019년 4월 25일

For teams to do their best work, enterprises must empower them to be nimble and responsive in the face of new challenges and opportunities. But that kind of flexibility—across physical and virtual spaces, in remote and global locations, with internal and external teams—can often fly in the face of security concerns. That’s an assumption we plan to dispel.

Here at Slack, it is our deepest belief that you don’t have to sacrifice security in order to work with agility.

And with that in mind, today at Frontiers we shared an array of ongoing investments we’re making in security and compliance.

So while teams are busy being productive, administrators can rest assured that they have the tools they need to maintain control over their data security. Here’s a closer look at how each feature works.

Complete visibility into and control of your data in Slack using your own encryption keys

By default, Slack encrypts data at rest and data in transit as part of our foundational security controls. Slack Enterprise Key Management (Slack EKM) provides an extra layer of protection for our most security-conscious customers.

With Slack EKM, messages and files are encrypted using your own keys (stored in Amazon’s Key Management Service), thereby giving you complete control over your data in Slack. And what makes Slack EKM unique is that it’s designed to minimize disruptions across your organization, giving you the security control you need without sacrificing user experience and productivity.

Only one month after making Slack EKM available, we already have some of the world’s most security-conscious customers benefiting from it, from government agencies and consulting companies to financial services firms. But don’t just take our word for it.

“Over the last year, we’ve worked closely with Slack specifically on security features around Enterprise Key Management and bring-your-own-key,” says Carmine Lizza, the chief information officer and global head of technology at the financial advisory firm Lazard. “Now that these are embedded into the enterprise solution, we can successfully adopt it and take advantage of its features.”

Further investments to help you meet your compliance requirements

We’re proud that Slack is where work happens for all sorts of organizations, including those in regulated industries and customers with other compliance needs.

Our offerings started out with SOC 2 and CSA certifications, and we’ve since expanded to include even more tools, controls and settings to help customers address their needs related to the following:

Today, we’re delighted to inform our customers in the health-care space that we’ve increased the scope of our HIPAA functionality, which now supports PHI (protected health information) not just in files but also in Slack messages.

Protect your data on unmanaged devices with native mobile security controls

With the workforce being increasingly distributed and on the go, mobile security has never been more important. So to complement our Slack for Enterprise Mobility Management offering, we’re building more native mobile security controls to ensure that data remains secure even on a device that isn’t managed. Here’s what’s in store:

  • Block Download and Copy: With this new feature, admins have the ability to configure Slack to block all file downloads and message copy to mobile devices in order to better control data exfiltration
  • Secondary Authentication: To make sure only the right people are accessing the Slack mobile app on an ongoing basis, this feature requires users to use Face ID, Touch ID or a passcode before accessing the app
  • Session Management: This feature gives admins control over mobile sessions, including the ability to remotely wipe sessions to ensure that data remains secure in the event that a device is lost or stolen

More visibility, more control, more compliance. Who says that large or highly regulated enterprises can’t operate just as nimbly as their smaller counterparts? Not us, that’s for sure.

To learn more about our robust security initiatives and compliance certifications, check out slack.com/security.

The following information is intended for INFORMATIONAL PURPOSES ONLY, and not as a binding commitment. Please do not rely on this information in making your purchasing decisions. The development, release and timing of any products, features or functionality remain at the sole discretion of Slack, and are subject to change.

이 포스트가 유용했나요?

0/600

훌륭해요!

피드백을 주셔서 감사합니다.

알겠습니다!

피드백을 주셔서 감사합니다.

죄송합니다. 문제가 발생했습니다. 나중에 다시 시도해주세요.

계속 읽기

새 소식

모든 정보를 찾기 위한 Slack 엔터프라이즈 검색을 소개합니다

Slack에서 귀사의 모든 지식과 데이터를 바로 검색할 수 있는 중앙 허브를 사용해 보세요.

협업

Slack으로 파트너 판매를 향상하는 세 가지 전략

자동화와 신속한 커뮤니케이션으로 기술 채널 판매 관계를 강화하는 방법

협업

Slack의 보안: Slack이 데이터를 보호하는 방법

Slack의 최우선 가치는 고객 신뢰 유지입니다. Slack이 조직의 안전과 생산성을 유지하는 방법을 알아보세요.

변환

Slack, Dreamforce에서 에이전트 시대를 위한 혁신을 공개하다

디지털 에이전트 시대에 Slack의 업무용 운영 체제를 통해 조직이 어떻게 성공할 수 있는지 자세히 알아보세요.