|
|
|
|
|
The compact design that makes smartphones so attractive also makes them susceptible
to theft, loss and potential intrusion. The implications of always on, everywhere
mobility are just beginning to be understood.
Millions of mobile devices are accessing confidential corporate data, and the security
risks associated with this increasing population of devices are real. A comprehensive
security management system must provide data security and device security. How is
theft or loss of a mobile device managed? What provisions are in place for recovery
procedures? What safeguards are provided for device or data misuse?
|
|
|
|
Leading companies understand that smartphone security and management issues are
complex and evolving rapidly. They need a mobile business partner who has an in-depth
understanding of the ongoing complexity of security management with a track record
that demonstrates that expertise.
|
|
|
|
Three key areas must be considered for assessing the management of mobile devices—security,
risk avoidance and risk management:
|
|
|
|
Security |
|
|
- Company provides dedicated smartphones (recommended for maximum
security)
- Central management of entire device fleet with inventory of devices
and phone contents
- Central focus for reporting lost, stolen or at risk devices
- Security settings and policies established to prevent unauthorized
actions
- Client processes applied to mobile devices for administering security
settings and policies
- Encrypted over the air (OTA) installation of all software and settings
- Login only with username and password authenticated by Active Directory,
or other LDAP provider
- Erase all data and settings after a preset number of invalid login
attempts
- Erase all data and settings on the device remotely if the device
is lost or stolen
- No user access to critical folders and directories
- Control access to applications and network connections (Bluetooth,
cable, etc.) on device
- Company recommended software, including browser and secure access
to Web via company proxy server (if Web access authorized)
- Support for mobile VPN
|
|
|
|
Risk Avoidance |
|
|
- Rapid replacement and configuration of lost or stolen devices
- Enable reinstallation with a text message to phone from administrator
- Enable a full reset of phone with data recovery from server
- Application menu/screen simplified by removing all unnecessary
programs
- Disable actions considered to be unsafe (Access to system trays,
directories and applications specified
- All certificates and user settings for VPN, proxy server, and line
of business data and applications applied to device properly credentialed
|
|
|
|
Risk Management |
|
|
- Replacement of employee owned phones with secure company smartphones
- Sign in only with authenticated company identity information
- Company can be broken into groups with different security requirements
and authorizations
- Download of appropriate line of business applications based on
group and experience level
- Ease of use and Web user interface enable multiple administrators
to be trained, with no programming capability required
- Avoid exposure of unsecured customer data on lost or stolen phone
|
|
|