NIST Drafts Mobile App Security Guidelines - InformationWeek
Government // Mobile & Wireless

NIST Drafts Mobile App Security Guidelines

National Institute for Standards and Technology issues first draft of guidelines intended to help federal agencies balance benefits and risks of third-party mobile apps.

Comment  | 
Print  | 
Newest First  |  Oldest First  |  Threaded View
User Rank: Ninja
8/30/2014 | 6:22:43 PM
Why no Guidelines for Windows or Blackberry Apps?
I was very surprised that NIST did'nt take the time and effort to also come up with Effective Guidelines List for Windows and RIM.

Sure,I am not disputing that Android and iOS are easily the dominant Mobile OSes(who control more than 70% of the smartphone market between themselves currently) but the other Two OSes are not something which can and should be neglected going ahead.

Windows in particular is finally gaining traction(especially at the Low-End) and I won't be surprised if they do go head to head with Android in the next 2 years or so.

The Lumia range is definitely turning heads currently and the HTC One Windows Phone is very catchy too.

What happens then?

Why not more coverage?

Lets also not forget the massive weakness in Smartphone Memory which was recently exploited at Defcon to show easy it is to break into Gmail App and many other such similar apps.

The Other apps hacked included H&R Block, Newegg, WebMD, Chase Bank, and Amazon.

I am hoping NIST does'nt take this issue lightly.

After all,the pace at which Android Malware is exploding(almost in tandem with increased Android Adoption) knows no bounds currently.

Alternative Mobile OSes need to see much coverage primarily because Privacy Conscious Consumers will look for them.

Even Samsung recently decided to push TIZEN in tandem with Intel .

We definitely do need more App Stores and OSes covered than just the Big Two.


User Rank: Ninja
8/30/2014 | 6:01:40 PM
Re: Mobile app security can't just be a government problem

I have a strong feeling that you are quite right and accurate here.

Most Organizations don't have the time and inclination to go through all the Apps Permissions Jargon and what not for most Employees.

They would rather just hand them the Phones and ask them to get on with the Job.

The end result can end up being very scary and disastrous for all concerned.

Sad but true.


User Rank: Ninja
8/30/2014 | 5:32:11 PM
Re: NIST Guidelines Not Very Realistic

Actually if One looks at these Guidelines(Given that they are almost exclusively aimed at Public Sector Enterprises),its a good list.

It forces not just in-house App Developers (at Public Sector Companies)but also anyone targetting Public Sector Companies to develop less Privacy Intrusive Apps if they want to gain such traction there.

I think its a really-really great list and should be enforced strongly by Individual IT Departments.


User Rank: Ninja
8/28/2014 | 5:01:16 PM
NIST Guidelines Not Very Realistic
The problem with the NIST guidelines is that every single app demands access to contacts, among other intrusive rights demanded.  Of course, the user has the option of not granting that particular privilege, in which case, the app just won't install/work correctly.  
David F. Carr
David F. Carr,
User Rank: Author
8/28/2014 | 4:32:37 PM
Mobile app security can't just be a government problem
I suspect to a large extent enterprises outside of the public sector are in no better shape for assessing the security of mobile apps.
How Enterprises Are Attacking the IT Security Enterprise
How Enterprises Are Attacking the IT Security Enterprise
To learn more about what organizations are doing to tackle attacks and threats we surveyed a group of 300 IT and infosec professionals to find out what their biggest IT security challenges are and what they're doing to defend against today's threats. Download the report to see what they're saying.
Register for InformationWeek Newsletters
White Papers
Current Issue
2017 State of the Cloud Report
As the use of public cloud becomes a given, IT leaders must navigate the transition and advocate for management tools or architectures that allow them to realize the benefits they seek. Download this report to explore the issues and how to best leverage the cloud moving forward.
Twitter Feed
InformationWeek Radio
Archived InformationWeek Radio
Join us for a roundup of the top stories on for the week of November 6, 2016. We'll be talking with the editors and correspondents who brought you the top stories of the week to get the "story behind the story."
Sponsored Live Streaming Video
Everything You've Been Told About Mobility Is Wrong
Attend this video symposium with Sean Wisdom, Global Director of Mobility Solutions, and learn about how you can harness powerful new products to mobilize your business potential.
Flash Poll