Bringing mobility into business

August 2012 Information Security

The proliferation of Apple iOS and Android based mobile computing devices is significant, not only in the consumer space, but also in the office. People are quick to gravitate to the ease of use, increased mobility and portability with access to applications anywhere any time.

Businesses have to contend with the fact that executives and users are eager to show off their new toys. Therefore the demands to ensure that these user owned devices are linked to company e-mail and scheduling systems are high, but doing so may be exposing organisations to uncalled-for risks.

Common approaches to this are to look at the risks, define a policy and deploy a technical control so that you gain some form of visibility into the BYOD (bring your own device) space. My view differs in the approach in that we need to follow a higher-level methodology as well as a more detailed plan of action and risk management.

A high-level principle statement needs to be defined. Here we can agree to accept or deny the proliferation of BYOD, with the proviso that if we block user owned devices, only company owned devices will be acceptable.

Define a policy based on the company business requirements as well as how the various categories within the workforce (sales or technical support staff may have widely differing access and application needs) will interact with company resources and data. Within the policy, we may define exceptions to accompany user owned devices, but this should be strict in that it will be treated as a company owned device, with little or no regard for user owned content in case a remote wipe or other management action is pushed to the device.

Technical control. The official category was defined as Mobile Device Management (MDM). These tools make it easy to centralise mobile device policy definition and device management.

Having a data classification policy in place will be a requirement. You should evaluate how mobile devices may impact your current data classification policy, as you may find that you are in active violation of your data governance guidelines.

Contrary to popular belief, most MDM solutions can be implemented at an efficient price per user for even small numbers of users, allowing SMEs to embrace new ways of doing business. However, ensuring that they do not expose client data in ways that could have long-term financial impact, especially after we have our draft Protection of Personal information Bill approved.

Selecting an MDM tool

* Does the selected vendor support the operating systems on the most common devices (Windows Mobile and Slate, Apple iOS, BlackBerry, Android and Symbian)?

* What infrastructure do we need to deploy to manage the vendor provided solution? A popular MDM route to market is to offer a fully managed cloud-based solution.

* If the software is cloud based how are your administrators authenticated and are all communications encrypted?

* Can you define your own policies for device management and do they offer some samples to fast track your implementation?

* Can you enforce conditional device lock, remote wipe as well as geo-fencing so that a device that leaves a predefined geography will be automatically wiped?

* Does the MDM solution accommodate the Android Market, BlackBerry App World or Apple iStore, and can they assist you to publish your company approved applications?

* Can updates be scheduled through your MDM solution and does it include support for custom applications?

* Does the solution offer an ‘at a glance’ inventory of hardware and software with details such as devices type, OS versions, patch levels, free space, memory utilisation and applications installed?





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Highest increase in global cyberattacks in two years
Information Security News & Events
Check Point Global Research released new data on Q2 2024 cyber-attack trends, noting a 30% global increase in Q2 2024, with Africa experiencing the highest average weekly per organisation.

Read more...
From QR code to compromise
Information Security News & Events
A new attack vector involves threat actors using fraudulent QR codes emailed in PDF attachments to bypass companies' phishing security measures by requiring users to scan the code with their mobile phones.

Read more...
Organisations fear AI-driven cyberattacks, but lack key defences
Kaspersky Information Security News & Events Training & Education
A recent Kaspersky study reveals that businesses are increasingly worried about the growing use of artificial intelligence in cyberattacks, with 56% of surveyed companies in South Africa reporting a rise in cyber incidents over the past year.

Read more...
Vodacom Business unveils new cybersecurity report
Information Security IoT & Automation
Cybersecurity as an Imperative for Growth offers insights into the state of cybersecurity in South Africa, the importance of security frameworks in digital resilience and the latest attack methods adopted by cyberattackers.

Read more...
Smart surveillance and cyber resilience
Axis Communications SA Surveillance Information Security Government and Parastatal (Industry) Facilities & Building Management
South Africa’s critical infrastructure sector has to step up its game regarding cybersecurity and the evolving risk landscape. The sector has become a prime target for cybercriminals on top of physical threat actors, and the consequences of an incident can be far-reaching.

Read more...
NIS2 compliance amplifies skills shortages and resource strain
Information Security Security Services & Risk Management
A new Censuswide survey, commissioned by Veeam Software reveals the significant impact on businesses as they adapt to this key cybersecurity directive, with 95% of EMEA businesses siphoning other budgets to try and meet compliance deadline.

Read more...
Know who’s spying on you
Kaspersky Information Security Products & Solutions
According to the latest State of Stalkerware report, 40% of the people surveyed worldwide stated they have experienced stalking or suspect they are being spied on. A solution for Android is now available.

Read more...
Cybersecurity needs 4,7 million professionals
Information Security
Despite all the efforts organisations worldwide put into preventing cyberattacks, global cybercrime has snowballed to $9,2 trillion in 2024 and is expected to grow by another 70% to $15,6 trillion by the end of a decade.

Read more...
Autonomous healing systems are the future
Infrastructure Information Security AI & Data Analytics
Autonomous healing software, an emerging technology, is gaining traction for its potential to transform how organisations manage software maintenance, security, and system performance.

Read more...
Understanding South Africa’s Cybercrimes Act
Information Security Security Services & Risk Management
The Cybercrimes Act No.19 of 2020 is a comprehensive legislative response to the evolving landscape of cyberthreats in South Africa. Its effectiveness, however, relies on enforcement, which relies on implementation, international cooperation, and collaboration between the public and private sectors.

Read more...