Home
Craig Mathias

Craig Mathias



Why Security Isn't A BYOD Showstopper

Comments | Craig Mathias, InformationWeek | May 08, 2012 09:05 AM


9 Hottest Phones At Mobile World Congress
9 Hottest Phones At Mobile World Congress
(click image for larger view and for slideshow)
In a webinar on BYOD that I just did, a survey of the 500-plus participants showed that security is the way-out-in-front, lead concern of IT managers when it comes to implementing a bring-your-own-device program. More than 60% of those people voting reiterated what I hear every day. "Is it safe? Can we really trust users and their personal handsets with enterprise secrets?"

Security is, of course, the one part of IT where one can never be "done". Each week brings new concerns, new threats, and some previously unknown and unforeseeable challenge. Perhaps it's news of yet another IT breach, or, even worse, a discovery, not yet public, that something has gone terribly wrong and confidential information might be compromised. With security constantly under fire, then, aren't we just making things worse by allowing essentially any device on the corporate network? Aren't we just waving the proverbial red flag in front of the hacker community, daring them to do their worst once again?

More Insights

Webcasts

More >>

White Papers

More >>

Reports

More >>

Let me begin to answer that by saying that BYOD is, no matter what, going to become the norm in enterprise mobility during the next few years. Users want to carry only one handset, and it's their phone. The enterprise can save big bucks by eliminating the capital expense of unwanted (by users, anyway) handsets and sharing the operating expense of cellular service plans. Properly managed, then, BYOD looks like a win/win.

[ Read BYOD: How To Calculate Hidden Security Costs. ]

And proper management is the key. A number of vendors have announced BYOD solutions in recent days. Although each of these products addresses security, they are really at their cores about policy, and the enforcement thereof. So, then, is your security policy in place and up-to-date? How about your acceptable-use policy? Your agreements with your employees and contractors regarding the above and service-cost reimbursements? Have you updated your training? Training includes, by the way, basic consciousness-raising, along the lines of "loose lips sink ships".

As is always the case in IT, the place to start is with strategies and objectives; many questions need to be asked before any IT service goes live, let alone with BYOD. What information should be secured? Who should have access to it, and under what circumstances? What must be done in the event of a breach? How is confidential information tracked? What are the policies regarding authentication, file encryption, remote access, and VPNs?

All BYOD does is introduce a potential new vector; it doesn't redefine or even change the security problem very much. Got live USB ports on your PCs? Know how much a modern microSD card can hold? Still think BYOD is that big of a security threat?

We can learn a lot from the techniques employed in government-class security, which are based on the concepts of security clearance level (secret, top secret, etc.) and, more importantly, need to know. The former can be addressed through a careful and at least annual review of security policy and procedures, along with the tools applied. Need to know is addressed by carefully defining and controlling who belongs to what group of users, and what privileges are granted to any given group. See? BYOD doesn't really introduce much new here.

Indeed, a good BYOD solution is one coupled with mobile device management (MDM) and mobile application management (MAM) capabilities to make sure that mobile devices allowed on the corporate network are operationally secured and appropriately monitored, and that features such as device wipe are available when necessary (and, of course, that users are aware they might be applied).

I see BYOD evolving from Guest Access 2.0 to, ultimately, the enterprise network access control system of the future. The core functions in BYOD, which can include, depending upon enterprise philosophy and vendor implementation, all aspects of both security and integrity management, are common to both wired networks and enterprise-owned devices as well.

So perhaps we should view BYOD as less of a novelty or a threat, and more as an opportunity to improve security, cut costs, and, in the bargain, improve both user and operations-staff satisfaction across the board.

At this interactive Enterprise Mobility Virtual Event, experts and solution providers will offer detailed insight into how to bring some order to the mobile industry innovation chaos. When you register, you will gain access to live webcast presentations and virtual booths packed with free resources. It happens May 17.

Craig Mathias is a Principal with Farpoint Group, a wireless and mobile advisory firm based in Ashland, MA. Craig is an internationally recognized expert on wireless communications and mobile computing technologies. He is a well-known industry analyst and frequent speaker at industry conferences and trade shows.



Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

BYTE encourages readers to engage in spirited, healthy debate, including taking us to task. However, BYTE moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. BYTE further reserves the right to disable the profile of any commenter participating in said activities.

COMMENTS

Tune In to BYTE
Facebook Twitter LinkedIn Newsletter RSS
Whitepapers
whitepaper
In this paper you will learn the five trends shaping the future of enterprise mobility. Learn how the rise of social media as a business application, the lurring between work and home, the emergence of new mobile devices, the demand for tech savvy employees and changing expectations of corporate IT will fundamentally change the workplace.
whitepaper
In a survey of more than 1,700 information workers (iWorkers) in North America, notebooks, desktops, and smartphones were found to be “must-have” devices, while tablets, slates, and netbooks were relegated to “nice-to-have” status, according to a commissioned study conducted by Forrester Consulting on behalf of Dell and Intel.
Sponsored by: Dell
Upcoming Events