C.11 Email Management Policy

Version: April 2025
Applies to: All employees, contractors, and stakeholders
Aligned with: ISO/IEC 27001:2022 (A.5.7, A.8.12, A.8.16, A.8.23)

Purpose
To ensure all organizational email communication is protected from spam, malware, phishing, and data leakage — reducing risk and preserving system integrity.

1. Scope
Applies to:
- All inbound and outbound email
- All devices and email clients used to send or receive company mail
- All filters, monitoring systems, and DNS protections for organizational email domains

2. Core Email Security Requirements

ID Requirement
EM-01 Maintain an inventory of authorized email domains
EM-02 List all approved Mail Transfer Agents (MTAs)
EM-03 Enforce proper DNS settings (SPF, DKIM, DMARC) per domain
EM-04 Require TLS encryption for all server-to-server email communication
EM-05 Block inbound emails from domains missing valid DNS records
EM-06 Perform spam filtering on all emails (inbound and outbound)
EM-07 Scan emails for malware
EM-08 Apply anti-phishing filters to all messages
EM-09 Scan for malicious URLs in email bodies
EM-10 Filter for sensitive or policy-violating content in emails
EM-11 Scan attachments, including sandboxing for unknown file types
EM-12 Use a separate file transfer portal for large or sensitive file exchanges outside email systems

3. Enforcement & Sanctions
Failure to comply may result in:
- Mandatory training or access restrictions
- Contract termination or legal action

Direct URL: