Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Perimeter

Guest Blog // Selected Security Content Provided By Sophos
What's This?
7/17/2013
01:04 PM
Maxim Weinstein
Maxim Weinstein
Security Insights
50%
50%

Forget Standardization -- Embrace BYOD

The platform standardization ship has sailed, but mobile device management is your ticket to securing all of those handhelds

Despite its rocky start, Windows 8 has IT departments salivating over the idea of standardizing on a single platform. It's a compelling vision: phones, tablets, and workstations all running a single OS and managed through a shared set of native Microsoft tools. Compelling, perhaps, but for most organizations, it ain't gonna happen.

Except in the most locked down, high security environments, platform standardization is quickly becoming a thing of the past. The social marketing guru you hired is joined at the hip to his shiny, new Galaxy S4. If you want him tweeting and posting off-hours, it's Android or bust. The new marketing director? He gave up Windows five years ago and wants a MacBook Air. And when the CEO wants to check her email on her iPad, good luck convincing her that she should trade it in for a Surface tablet.

In five years, according to Gartner, 70 percent of mobile workers will use personal smart devices to do their work. Whether driven by business agility, employees' connections to their consumer devices, or cost savings, bring your own device (BYOD) is becoming a reality. The forward-thinking IT leader, then, isn't trying to standardize on Windows or any other platform. Instead, he's looking at how he can manage and secure a diverse array of company-owned and personal devices.

For those of us in security, this requires a difficult mind shift. When we don't own the device, the software running on it, or the network it's communicating on, how do we do our jobs? The answer, it turns out, is to focus on policy. Remember when you learned that the first step in architecting security is to develop a solid security policy? This is truer today than ever before. In a monolithic corporate computing environment, you can enforce policy -- or even de facto create it -- simply by configuring devices a certain way and preventing users from changing the configuration. Now, policy must become a gatekeeper: Employees can use any device to access corporate data or systems as long as the device is compliant with the security policy.

Today's mobile device management (MDM) tools allow you to enforce a variety of policy items, such as requiring devices to have antivirus software and to scan newly installed apps; setting minimum length and complexity of unlock passwords; encrypting data on the devices; empowering IT to remotely lock or wipe devices in case of loss or theft; and prohibiting rooted or jailbroken devices.

Think, for a moment, about how empowering this shift really is. For your users, it means they have the latitude to choose the phone or tablet that works best for them, regardless of OS. They don't have to carry around two phones, one for work and one for home. And they can change phones or even platforms whenever they like. For you and your IT colleagues, it means freedom from purchasing, deploying, and supporting devices. Communicate the policy, provide your users with a process to install the MDM tool (e.g., via a self-service portal), and let them loose.

It's time to stop dreaming of the halcyon days of BlackBerry or bust, and to stop fantasizing about Microsoft's one platform to rule them all. BYOD is here, and with it comes the new challenge of securing more devices, on more platforms, with more user freedom. Fortunately, with some planning and the right tools, you can simultaneously provide security and add value to your business and employees.

Now that is an idea that IT departments should be salivating over. Maxim Weinstein, CISSP, is a technologist and educator with a passion for information security. He works in product marketing at Sophos, where he specializes in server protection solutions. He is also a board member and former executive director of StopBadware. Maxim lives ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
loganfrye951
50%
50%
loganfrye951,
User Rank: Apprentice
8/11/2013 | 1:45:38 PM
re: Forget Standardization -- Embrace BYOD
I agree, standardization is a thing of the past with BYOD. IT departments are going to have to get used to the fact that BYOD means very little standardization, and if they want to 'standardize' then they are going to have to get inventive. Our hospital is a good example of this; as we are taking a HIPAA compliant texting API by Tigertext called TigerConnect, and putting it together with a secure email API and the Dropbox API to make a security app that all the staff, interns and doctors will install on their phones and tablets to ensure HIPAA compliance and security. This app will work on all platforms, so in a sense itGs a form of standardization in order to meet HIPAA compliance.
Cara Latham
50%
50%
Cara Latham,
User Rank: Apprentice
8/7/2013 | 8:02:42 PM
re: Forget Standardization -- Embrace BYOD
I agree. People are creatures of habit. They have preferences for various devices, and if they are more comfortable working with a particular one, they will be more productive. This also cuts down on costs for the company.
GarretG022
50%
50%
GarretG022,
User Rank: Apprentice
7/25/2013 | 2:27:24 AM
re: Forget Standardization -- Embrace BYOD
Why do you need a MDM to enforce access/authorization rules? Especially when you even stated - the corporation does not own the device.

The real way is to enforce application access control - based on corporate access rules.

http://www.secureauth.com/blog...
Adam2IT
50%
50%
Adam2IT,
User Rank: Apprentice
7/18/2013 | 1:28:09 PM
re: Forget Standardization -- Embrace BYOD
MDM is only one aspect of BYOD management. But what about helping IT staff support a wide range of devices, or ensuring that employees can connect to their work applications?

What's needed is a way to deliver applications to all types of devices while minimizing hassles for IT. For example, Ericom's AccessNow HTML5 RDP client enables remote users to securely connect from iPads, iPhones, Android devices, Chromebooks and more traditional laptops and PCs to any RDP host, including Terminal Server and VDI virtual desktops, and run their applications and desktops in a browser. AccessNow doesn't require any software installation on the end user device G just an HTML5 browser, connection and login credentials. An employee that brings in their own device merely opens their HTML5-compatible browser and connects to the URL given them by the IT admin.

Visit http://www.ericom.com/BYOD_Wor... for more info.

Please note that I work for Ericom
anon6876801533
50%
50%
anon6876801533,
User Rank: Apprentice
7/17/2013 | 7:07:12 PM
re: Forget Standardization -- Embrace BYOD
Couldn't agree more. People always want to work with the latest and greatest new gadgets. If they're willing to buy it themselves, why would a company not embrace that? Rather than put the money into a standard, and usually outdated, mobile platform, put the money into a MDM and have have happier employees.
News
FluBot Malware's Rapid Spread May Soon Hit US Phones
Kelly Sheridan, Staff Editor, Dark Reading,  4/28/2021
Slideshows
7 Modern-Day Cybersecurity Realities
Steve Zurier, Contributing Writer,  4/30/2021
Commentary
How to Secure Employees' Home Wi-Fi Networks
Bert Kashyap, CEO and Co-Founder at SecureW2,  4/28/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-35519
PUBLISHED: 2021-05-06
An out-of-bounds (OOB) memory access flaw was found in x25_bind in net/x25/af_x25.c in the Linux kernel version v5.12-rc5. A bounds check failure allows a local attacker with a user account on the system to gain access to out-of-bounds memory, leading to a system crash or a leak of internal kernel i...
CVE-2021-20204
PUBLISHED: 2021-05-06
A heap memory corruption problem (use after free) can be triggered in libgetdata v0.10.0 when processing maliciously crafted dirfile databases. This degrades the confidentiality, integrity and availability of third-party software that uses libgetdata as a library. This vulnerability may lead to arbi...
CVE-2021-30473
PUBLISHED: 2021-05-06
aom_image.c in libaom in AOMedia before 2021-04-07 frees memory that is not located on the heap.
CVE-2021-32030
PUBLISHED: 2021-05-06
The administrator application on ASUS GT-AC2900 devices before 3.0.0.4.386.42643 allows authentication bypass when processing remote input from an unauthenticated user, leading to unauthorized access to the administrator interface. This relates to handle_request in router/httpd/httpd.c and auth_chec...
CVE-2021-22209
PUBLISHED: 2021-05-06
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.8. GitLab was not properly validating authorisation tokens which resulted in GraphQL mutation being executed.