<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic US organisations blocking email based on location in Industry News</title>
    <link>https://community.isc2.org/t5/Industry-News/US-organisations-blocking-email-based-on-location/m-p/11736#M1137</link>
    <description>&lt;P&gt;Has anyone else come across organisations blocking email based on geographic locations recently, as a cyber security measure? For example US organisation only allowing email from within the US based on IP location.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Adam&lt;/P&gt;</description>
    <pubDate>Mon, 09 Oct 2023 08:49:49 GMT</pubDate>
    <dc:creator>4d4m</dc:creator>
    <dc:date>2023-10-09T08:49:49Z</dc:date>
    <item>
      <title>US organisations blocking email based on location</title>
      <link>https://community.isc2.org/t5/Industry-News/US-organisations-blocking-email-based-on-location/m-p/11736#M1137</link>
      <description>&lt;P&gt;Has anyone else come across organisations blocking email based on geographic locations recently, as a cyber security measure? For example US organisation only allowing email from within the US based on IP location.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Adam&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 08:49:49 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/US-organisations-blocking-email-based-on-location/m-p/11736#M1137</guid>
      <dc:creator>4d4m</dc:creator>
      <dc:date>2023-10-09T08:49:49Z</dc:date>
    </item>
    <item>
      <title>Re: US organisations blocking email based on location</title>
      <link>https://community.isc2.org/t5/Industry-News/US-organisations-blocking-email-based-on-location/m-p/11761#M1146</link>
      <description>&lt;P&gt;Adam,&lt;/P&gt;&lt;P&gt;Why do you ask? Are you simply curious if anyone is using IP group as a e-mail filter rule, or are you considering doing so, yourself?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Blocking by IP and domain are both legitimate ways to manage e-mail filter rules, but actually making the rules work correctly is very tricky, given the ability to spoof e-mail header information. There is a particular challenge in filtering MS Exchange Outlook format mail that has been processed through the Office 365 infrastructure, which layers multiple intermediate addresses in the ridiculously complex header.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 23 Jun 2018 13:21:13 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/US-organisations-blocking-email-based-on-location/m-p/11761#M1146</guid>
      <dc:creator>CraginS</dc:creator>
      <dc:date>2018-06-23T13:21:13Z</dc:date>
    </item>
    <item>
      <title>Re: US organisations blocking email based on location</title>
      <link>https://community.isc2.org/t5/Industry-News/US-organisations-blocking-email-based-on-location/m-p/11772#M1148</link>
      <description>&lt;P&gt;Thanks. I ask because some companies we work with are doing this and we cannot email them anymore, being UK based. I agree it is not a great way to secure, but we now need to find technical solutions or convince them otherwise.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just wondered if anyone else has had similar issues, who operate outside the US and email US based companies.&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/780103681"&gt;@CraginS&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Adam,&lt;/P&gt;&lt;P&gt;Why do you ask? Are you simply curious if anyone is using IP group as a e-mail filter rule, or are you considering doing so, yourself?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Blocking by IP and domain are both legitimate ways to manage e-mail filter rules, but actually making the rules work correctly is very tricky, given the ability to spoof e-mail header information. There is a particular challenge in filtering MS Exchange Outlook format mail that has been processed through the Office 365 infrastructure, which layers multiple intermediate addresses in the ridiculously complex header.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Adam&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jun 2018 09:23:59 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/US-organisations-blocking-email-based-on-location/m-p/11772#M1148</guid>
      <dc:creator>4d4m</dc:creator>
      <dc:date>2018-06-25T09:23:59Z</dc:date>
    </item>
    <item>
      <title>Re: US organisations blocking email based on location</title>
      <link>https://community.isc2.org/t5/Industry-News/US-organisations-blocking-email-based-on-location/m-p/11777#M1152</link>
      <description>&lt;P&gt;I haven't worked with US based organisations but I have previously implemented blocking by country. The questions I asked my users was 'Do you have any legitimate users who would need to access your application from North Korea, China, or Russia?' If the answer was 'No' I set the WAF to disable access from these countries. In fact for some systems the answer was that no-one outside of Europe should be normally be accessing the particular application so I restricted access to European countries only. I believe its a good measure to implement but you need to discuss and agree the access requirements with the system owners.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jun 2018 13:45:48 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/US-organisations-blocking-email-based-on-location/m-p/11777#M1152</guid>
      <dc:creator>Brids</dc:creator>
      <dc:date>2018-06-25T13:45:48Z</dc:date>
    </item>
    <item>
      <title>Re: US organisations blocking email based on location</title>
      <link>https://community.isc2.org/t5/Industry-News/US-organisations-blocking-email-based-on-location/m-p/11814#M1162</link>
      <description>&lt;P&gt;Blocking traffic with source IP addresses of&amp;nbsp;other countries will likely end up blocking a lot of legitimate traffic and not do much to stop malicious emails.&amp;nbsp; Nefarious actors are well aware of how to spoof IPs or&amp;nbsp;use proxy servers and VPNs to make it seem like they are coming from another location entirely.&amp;nbsp; It's a lot like MAC filtering your home router...it'll add a few steps when you want to add a new device but not do much to stop the kid next door with the Kali box and 10-minutes of YouTube education.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jun 2018 02:57:01 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/US-organisations-blocking-email-based-on-location/m-p/11814#M1162</guid>
      <dc:creator>DAlexander</dc:creator>
      <dc:date>2018-06-27T02:57:01Z</dc:date>
    </item>
    <item>
      <title>Re: US organisations blocking email based on location</title>
      <link>https://community.isc2.org/t5/Industry-News/US-organisations-blocking-email-based-on-location/m-p/11816#M1163</link>
      <description>I agree with you to the extent that no security gives you 100% protection but you can make things more difficult for an opportunistic attacker. From implementing the policy I’ve recommended I experienced no legitimate users complaining of being locked out, and I could see from the SIEM dashboard that I had blocked a number of attempted accesses from countries blacklisted, and as system owners could not explain why anyone would want access from these countries I have to assume they were malicious.&lt;BR /&gt;&lt;BR /&gt;Sent from my iPad</description>
      <pubDate>Wed, 27 Jun 2018 06:58:33 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/US-organisations-blocking-email-based-on-location/m-p/11816#M1163</guid>
      <dc:creator>Brids</dc:creator>
      <dc:date>2018-06-27T06:58:33Z</dc:date>
    </item>
    <item>
      <title>Re: US organisations blocking email based on location</title>
      <link>https://community.isc2.org/t5/Industry-News/US-organisations-blocking-email-based-on-location/m-p/11836#M1167</link>
      <description>&lt;P&gt;Used to be a fairly common practice but also of a day when it was considered to be an effective way of slimming down some obviously bogus email. While reading the OP I thought of more than a few West African countries, Togo, Indian Ocean (.io) all come to mind as domains that I used to immediately blocked much like blocking China Backbone or if you remember the notorious 'Russian Business Federation' block of addresses.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Most anything can be turned into a game of whack-a-mole if you apply enough effort. This is really no different. Just remember to review your policies toward such on a periodic basis (Monthly, Quarterly, Annually... something different - as long as you see value in it.)&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jun 2018 18:33:34 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/US-organisations-blocking-email-based-on-location/m-p/11836#M1167</guid>
      <dc:creator>Beads</dc:creator>
      <dc:date>2018-06-27T18:33:34Z</dc:date>
    </item>
  </channel>
</rss>

