Government // Mobile & Wireless

NIST Drafts Mobile App Security Guidelines

National Institute for Standards and Technology issues first draft of guidelines intended to help federal agencies balance benefits and risks of third-party mobile apps.

Comment  | 
Print  | 
Newest First  |  Oldest First  |  Threaded View
User Rank: Ninja
8/30/2014 | 6:22:43 PM
Why no Guidelines for Windows or Blackberry Apps?
I was very surprised that NIST did'nt take the time and effort to also come up with Effective Guidelines List for Windows and RIM.

Sure,I am not disputing that Android and iOS are easily the dominant Mobile OSes(who control more than 70% of the smartphone market between themselves currently) but the other Two OSes are not something which can and should be neglected going ahead.

Windows in particular is finally gaining traction(especially at the Low-End) and I won't be surprised if they do go head to head with Android in the next 2 years or so.

The Lumia range is definitely turning heads currently and the HTC One Windows Phone is very catchy too.

What happens then?

Why not more coverage?

Lets also not forget the massive weakness in Smartphone Memory which was recently exploited at Defcon to show easy it is to break into Gmail App and many other such similar apps.

The Other apps hacked included H&R Block, Newegg, WebMD, Chase Bank, and Amazon.

I am hoping NIST does'nt take this issue lightly.

After all,the pace at which Android Malware is exploding(almost in tandem with increased Android Adoption) knows no bounds currently.

Alternative Mobile OSes need to see much coverage primarily because Privacy Conscious Consumers will look for them.

Even Samsung recently decided to push TIZEN in tandem with Intel .

We definitely do need more App Stores and OSes covered than just the Big Two.


User Rank: Ninja
8/30/2014 | 6:01:40 PM
Re: Mobile app security can't just be a government problem

I have a strong feeling that you are quite right and accurate here.

Most Organizations don't have the time and inclination to go through all the Apps Permissions Jargon and what not for most Employees.

They would rather just hand them the Phones and ask them to get on with the Job.

The end result can end up being very scary and disastrous for all concerned.

Sad but true.


User Rank: Ninja
8/30/2014 | 5:32:11 PM
Re: NIST Guidelines Not Very Realistic

Actually if One looks at these Guidelines(Given that they are almost exclusively aimed at Public Sector Enterprises),its a good list.

It forces not just in-house App Developers (at Public Sector Companies)but also anyone targetting Public Sector Companies to develop less Privacy Intrusive Apps if they want to gain such traction there.

I think its a really-really great list and should be enforced strongly by Individual IT Departments.


User Rank: Ninja
8/28/2014 | 5:01:16 PM
NIST Guidelines Not Very Realistic
The problem with the NIST guidelines is that every single app demands access to contacts, among other intrusive rights demanded.  Of course, the user has the option of not granting that particular privilege, in which case, the app just won't install/work correctly.  
David F. Carr
David F. Carr,
User Rank: Author
8/28/2014 | 4:32:37 PM
Mobile app security can't just be a government problem
I suspect to a large extent enterprises outside of the public sector are in no better shape for assessing the security of mobile apps.
Register for InformationWeek Newsletters
White Papers
Current Issue
Increasing IT Agility and Speed To Drive Business Growth
Learn about the steps you'll need to take to transform your IT operation and culture into an agile organization that supports business-driving initiatives.
Twitter Feed
InformationWeek Radio
Sponsored Live Streaming Video
Everything You've Been Told About Mobility Is Wrong
Attend this video symposium with Sean Wisdom, Global Director of Mobility Solutions, and learn about how you can harness powerful new products to mobilize your business potential.