Verint offers a certified, Cisco compatible compliance recording and data governance solution for Cisco Jabber/Unified Communications Manager including Jabber desktop and mobile endpoints. Our solution provides centralized capture, archiving, retrieval and analysis of interactions by any nominated user in your organization – including voice, IM, video and screen activities – while offering a variety of recording modes and supporting various conversation scenarios.
1. Demystifying Instant Message Compliance for Cisco Jabber
Legal compliance of internal and external communications are vital in regulated industries like the finance sector. When management and the compliance team asks for a Jabber IM compliance solution, they rarely mean ‘we need to store chats somewhere’.
They require a complete solution that supports the legal compliance team and ensures that the Compliance Officer in the company can reasonably demonstrate to any regulator, that safeguards, audits, privacy controls and effective search and analysis capabilities are in place, therefore regulatory requests can be answered timely (just think of MiFID II, Dodd-Frank, MAD and other regulations).
IM recording completes our collaboration recording portfolio for Cisco. The Cisco IM&P Server connects to the Verint Financial Compliance Capture (formerly known as Verba) recording solution, which plays the role of a Compliance Server in this scenario. Let’s see how it works.
Unified Search experience
The solution provides a unified search experience, where IM conversations are presented in the same view as your calls. This provides a great timeline view of complex conversations where the session starts with IM and is escalated into a call.
Instead of the play button of the Verint Media Player, on IM sessions a Conversation Viewer is presented, which shows the entire conversation. The solution stores the entire rich text / HTML conversation, currently a clear text representation is presented.
Full text search
The solution provides lightening fast full text search capabilities for instant messages, completely integrated with the traditional call search interface.
Complete IM compliance feature set
The Verint Financial Compliance recording solution provides the following:
- unified search – a single search experience for voice, video and IM conversations
- full text search – search in for millions of messages
- selective recording – you decide who should be recorded
- ongoing conversations – a list of all ongoing chat conversations together with all other ongoing calls
- IM monitoring – it is possible to view contents of ongoing IM sessions (silent monitoring for IM)
- per user IM recording – recording of all chat conversations from the view point of all participants
(including one-to-one and conference chats)
- compliance message – a message can be inserted into the beginning of all chat flows (e.g. this conversation is recorded for compliance reasons)
- mixed scenarios – support for all scenarios, when chat conversations are escalated into voice, screen capture and file transfers (although the transferred files themselves are not currently recorded)
- screen recording triggers – integration with the Verint screen recording capabilities to capture the entire screen of participants
- resiliency – recording sessions seamlessly continue after network downtime
- compliance stop – chat conversations can be prevented if recording is not operational
- multiple recorders – multiple IM recorders can be connected to one Verint Media Repository
- end-to-end encryption – sessions transferred between recorders and repository are encrypted
2. Comparing Cisco Jabber IM Compliance Options
Today let’s examine two options for Jabber legal compliance: the PostgreSQL and the Verint way.
Two main Jabber IM compliance architectures
When your compliance team or management asks for a Jabber IM compliance solution, they rarely mean: “let’s just store those chats somewhere”. The Verint solution not only records UC sessions, but provides the organization an end-to-end solution from recording to legal holds and long term archiving.
When you need Jabber IM compliance, you have essentially two options to achieve that. Both are Cisco supported standard design:
- PostgreSQL based – sending IM transactions into an open source PostgreSQL database
- Compliance Server based – using a third-party Compliance Server (like Verint) that connects to the Cisco IM and Presence Server
Both architectures have it’s place, organizations with different requirements and different ambitions will have to decide which one fits better.
The difference: first base vs homerun
The best way to demonstrate the difference is to use a baseball metaphor (please forget other related metaphors for a minute).
Using the PostgreSQL solution is useful and when it is done, you are one step closer to IM compliance: you can point to a database that stores all your IM messages. However, that is how far you got. There a couple of more bases to cover in most organizations. Some highlights of the PostgreSQL solution:
- requires an external PostgreSQL database (Cisco provides help for setting up PostgreSQL on a Linux server in Database Setup Guide for Cisco Unified Presence)
- you configure one or more external databases per Cisco cluster (see Configuring an External Database on Cisco Unified Presence chapter in the above database setup guide)
When you connect Presence Server to the database it will create the correct database schema automatically (a great feature). Accessing the database requires direct access to PostgreSQL. There are web-based solutions to access PostgreSQL (like phpPgAdmin), however those are providing low level access and is not really suitable for your compliance team.
Compliance Server based solution with Verint
The primary Jabber IM compliance architecture in the Verint Financial Compliance recording solution is based on a native compliance interface in the Presence Server. The standard Cisco diagram to the left shows this architecture. The compliance interface makes the following capabilities possible:
- selective recording – store only what is relevant or necessary
- compliance messages – directly injected into the message flow for your users to see
- filtering IM messages – phrase based redaction and filtering
- ethical wall – blocking IM for legal reasons
- technical blocking – blocking when recording is not available for any reason
While the current version of the Verint solution is not a full fledged ethical wall, it does have functionality for filtering, redaction and blocking.
Safeguard Legal Compliance with Verint
The added value does not stop there. Having the IM sessions stored in the Verint Media Repository (essentially a compliance store) gives the following advantages:
- web based access – there is no need to write a separate web interface or directly access a Linux-based database
- access control – you define who can see what, so multiple legal teams can work in the system without privacy or compliance issues
- auditing – all access to the solution is logged
- unified access to media – when IM, voice and video are all stored into Verint, these are presented in a unified way, in a single system
- built-in data retention – a comprehensive data retention system gives your compliance teams (even across state and country borders) total flexibility in defining retention rules for subsets of your recordings, no need to write scripts
- collaboration of legal team – your legal team can collaborate on recorded IM sessions by marking, tagging them and can work in a single system to find what they need
- legal hold support – the solution supports legal hold, to ensure necessary sessions are not deleted by data retention
The solution is Windows Server and Microsoft SQL Server-based and provides built-in monitoring methods, that makes it IT-friendly.
The above functions not only provide recording, but provides the organization a secure, audited, end-to-end solution from recording through legal hold management to long term archiving. One word: homerun.
Besides these, the Verint solution also supports many methods to record all aspects and media of Cisco Unified Communications, which makes it a future proof option for any team:
- Network port mirroring (voice, video)
- Phone based RTP forking (voice)
- Gateway API (XCC) based RTP forking (CUBE, TDM) (voice)
- CUBE based RTP forking (voice, video)
- Dial-in recording (voice, video)
- Proxy based recording (voice, video)
- MediaSense integration (voice)
- Jabber Compliance Server API (IM)
This comprehensive Verint technology portfolio means the compliance team will have a hard time coming up with new requirements that are not already covered by the solution (and when they do, our team reacts quickly). We call this approach, when IM, voice, video and desktop screens recording is done in a singe unified system: Collaboration Recording.
The difference between Legal Compliance and Storing Chats
When management and the compliance team asks for a Jabber IM compliance solution, they rarely mean ‘we need to store chats somewhere’. They need a complete solution that supports the legal compliance team and ensures that the Compliance Officer in the company can reasonably demonstrate to a regulator, that safeguards, audits, privacy controls and fast search and analysis capabilities are in place, therefore regulatory requests can be answered timely.
3. Custom Embedded Tab in the Cisco Jabber Client
The small form factor variant (mobile optimized) of the web interface in Verint can be embedded into a custom tab in the Cisco Jabber desktop clients, where it provides additional Jabber specific recording functionality right where you work. The Verint Financial Compliance compliance recording system directly supports Cisco Jabber Custom Embedded Tabs.
On the Verba/Verint tab, you can see information about your ongoing conversations (here you can decide to Record it, in case your account is not recorded constantly) and your last 10 conversations (all of your your voice, video and IM conversations are shown here for quick access). The tab can auto-refresh every time you open it to show the latest information in your last conversation list. It not only shows your Jabber desktop conversations, but also your desktop phone, mobile, etc. conversations you did using your Cisco UCM extension number or Jabber ID.
You can make simple searches by date period and number/address (you can type, phone numbers, names, email addresses). When you press Details, a summary page are presented with relevant details of your voice calls and IM conversations. The Playback function takes you directly to the Verint web interface, where you can take advantage of the rich feature set of the desktop version of the Verba web application.
Deploying the Cisco Jabber tab is solely a server-side configuration task. You can enable the Verba/Verint Cisco Jabber Tab for large amounts of users overnight. Using SSO support login can be automatic on Windows desktops, using Active Directory based single sign-on (no passwords required).
For more information, explore how to capture, store, retrieve and analyze calls via Cisco UC, collaboration, conferencing and telephony platforms. Additionally, the Automated Verification solution within Verint Financial Compliance offers automated infrastructure monitoring, call recording assurance, and voice quality testing capabilities for the Cisco Unified Communications Manager platform to help your business verify health, functionality, and performance of your critical communications environment.