If your job has anything to do with IT security, you're probably familiar with the importance of maintaining the confidentiality, integrity, and availability (CIA) of the systems for which you're responsible. These days, those systems are sure to include mail servers, most often Microsoft Exchange Server systems. Email is a business-critical application, and its security is a must. If you find yourself dealing with Exchange security—whether you're an Exchange administrator or a security pro—you first need to know how to measure the three CIA components as they relate to your messaging environment. After you know how to track the CIA of your Exchange servers, you can find ways to improve it. I'm going to concentrate on how to improve confidentiality and integrity rather than availability, which is a much broader and more-thoroughly documented topic. See the Related Reading box for articles that provide more information about availability and other topics in this article. . . .

