[an error occurred while processing this directive] [an error occurred while processing this directive]
[an error occurred while processing this directive]

[an error occurred while processing this directive]

















Tech Update Security
5 steps to secure mobile data
By Dave Neudoerffer, iAnywhere Solutions
November 7, 2002

TalkBack! Add your opinion

[an error occurred while processing this directive]

Mobile and wireless technology is revolutionizing how businesses use and profit from information. Employees outfitted with mobile devices, such as laptops and PDAs, can access valuable enterprise information when they're away from the office, which improves productivity, streamlines operations, and creates new revenue sources. But security is lacking.

While mobility is a competitive advantage, it means your data can travel beyond your secure LAN firewall and over public networks. Your security strategy needs to address the managing and securing of pervasive mobile data from end to end: whether it's stored on a mobile device, traveling over a wired or wireless network, or being sent back to the enterprise.

Organizations need to carefully consider mobile data security as a part of their mobile application development plans and work carefully with technology vendors that offer a complete security infrastructure for protecting mobile data, wherever that data may be. You should consider these five mobile security issues when developing and implementing mobile business solutions:

[an error occurred while processing this directive]
1. Protect against unauthorized users
The cornerstone of any security strategy, mobile or not, is user authentication. Any device attempting to exchange information with your corporate systems needs to have its identity verified. Each time the user goes deeper into a new area of sensitivity or functionality, your application and middleware infrastructure should know who they are, and whether they should be there.

  • Only the chosen may enter: A password should be required before a mobile user can synchronize with a back-end database or browse information stored on a company server--no exceptions. Use mobile device management software to ensure that users have not circumvented security measures or stored their password in a file on their device.
  • Rights and privileges: Define what clients can and cannot do. Depending on the application, specific rights and permissions are configured on a per-user basis. For example, a sales force automation application might allow a sales representative to submit orders, but not approve them. A sales manager's password would carry with it the authorization to view orders and approve or deny them.

2. Protect data transmissions
You might not be paranoid, but they are out to get you. Mobile applications require an exchange of information across a public network that is full of potential predators. When transmitting data, you need to ensure that it is secure from end-to-end. Any mobile middleware solution should operate on a secure connection for both data synchronization and client/server communications. Transport Layer Security (TLS) and Secure Sockets Layer (SSL) protocols allow a client application to verify the identity of a server, and ensure that they communicate only with servers they trust.

  • Tales from the encrypt: One of the simplest ways for someone to gain access to your data is to simply read the data stream between the mobile device and your server. Leverage strong 128-bit communications encryption to protect the confidentiality, integrity, and authentication of data packets as they pass between the client device and the server. This way, an identity thief who is reading a mobile banking customer's communications will hear only noise, not her bank balance, address, and PIN.
  • Know who you're talking to: How do you know that it's your bank on the other end, and not a server set up by a 16 year-old? Be certain that only authorized clients can connect to your server and that clients are connected to the correct server. During synchronization, or client/server connection through a browser, a password entered by the user indicates to the back-end system that they are an authorized user. A certificate on the internal database server tells the user's device that it is connected to the correct bank or hospital system. If your middleware doesn't provide this sort of functionality, it's like broadcasting your credit card information over the radio.
1 2 
Next page 

[an error occurred while processing this directive]
[an error occurred while processing this directive]




[an error occurred while processing this directive]
1. 5 steps to secure mobile data
2. Management tools, protecting investments


ARTICLES
Wireless security: not an oxymoron
Real products for real WLAN security
At last, real wireless LAN security
The hidden gotcha of built-in WiFi
PRODUCTS
Certicom Trustpoint PKI Portal
Sybase SQL Anywhere Studio
Lucent ORiNOCO
ISS Wireless Scanner





TECH UPDATE TODAY DAILY:
Dan Farber and David Berlind deliver daily insights on the business and technology news that matters to enterprise IT.


Enterprise Alerts
IT Management
IT Professionals
Online Shopping
System Administration
Linux

Manage My Newsletters





[an error occurred while processing this directive] [an error occurred while processing this directive]