Board logo

subject: Can Your Enterprise Security Handle The Mobile Challenge? [print this page]


Effective enterprise security includes knowing the mobile threat

How big is the challenge to enterprise security from mobile devices?

The problem of lost devices

A separate enterprise security problem is the number of mobile devices that are lost: in the UK some 10,000 mobile phones are left in London taxis every year and in the US, 11,000 laptops, tablets, smart phones and USB sticks were left in 5 airports in 2010. A recent Ponemon Institute study of 439 organizations found that 142,708 smartphones went missing in one year, representing 4.3% of those in use. Of the missing number, just 9,298 (6.5%) were recovered.

Limited security

This would be less of an enterprise security problem, had 60% of the lost phones not contained sensitive and confidential information and 57% been protected with available security features. This is a serious IT security and governance issue too because, according to the Carnegie Mellon study, half the mobile devices in use contain business data, passwords, PIN numbers and credit card information. There's a ton of concern both from individual users and IT organizations about mobile devices being lost or stolen, says Jamie Barnett of McAfee, and what happens to the corporate data on them.

Its far more serious than the smartphones lost by 439 organisations: according to a Juniper Networks Study, the vast majority of smartphone users anywhere dont use any antivirus software. These findings reflect a perfect storm of users who are either uneducated on or disinterested in security, said Dan Hoffman, Junipers chief mobile security evangelist. His final piece of advice is: Both enterprises and consumers alike need to be aware of the growing risks associated with the convenience of having the Internet in the palm of your hand.

Armed insiders

The threat of disgruntled or greedy employees leaking or stealing data is not new and not going away: insider data breaches make up between 20% (Verizon Data breach Report) and 43% (CSI Computer Crime Survey). Only now, with a smart mobile device and 24/7 access to the corporate network, the employee has the equivalent of a remote control in his hands. For enterprise security, thats a really tough one.

No acceptable use policy, DLP system or similar barrier will stop the insider if hes tech-savvy: he can configure RPC-over-HTTP to get around using the VPN for Outlook. And it's not just email, Brian Madden adds. It's web proxies to get around firewall rules. It's using Dropbox instead of file shares. It's a 3G card to avoid snooping networks ...

by: Astal mark




welcome to loan (http://www.yloan.com/) Powered by Discuz! 5.5.0