
|

|

|

|

 |
| Tech Update Security |
 |
5 steps to secure mobile data
Management tools, protecting investments
By Dave Neudoerffer, iAnywhere Solutions
November 7, 2002


[an error occurred while processing this directive] |
3. Protect data on lost devices
Mobile devices are small and expensive, so they are easily lost or left in taxis, and are a favorite target for thieves. If you don't want the new owner to have access to your corporate systems or view sensitive data, precautions must be taken.
- Persistent data needs persistent protection: There are two precautions that you can take to prevent disclosure of the data stored on a mobile device: encrypting sensitive data, and encrypting the entire file system (this may be useful when using data outside of a database, such as in a spreadsheet). Protect data that is stored on hard disks, in persistent memory, or on removable flash cards (whether they are in or out of the device).
- Always on duty: Even if the data store is protected, you risk exposing the information to unauthorized users if the application has cached data. Data that is stored in an application's memory is more difficult to access, but may also be exposed. Further, if your application sends updates that appear on-screen, the data contained in them may be available to anyone who turns on the device. Include a password-protected timeout in your applications but do not store it on the device; otherwise, anyone who has access to the device may be able to access your data.
| [an error occurred while processing this directive] |
4. Protect mobile assets
Safeguard your mobile assets such as your machines, devices, and data through centralized management. From a central location, you can simplify the enforcement of your security policy on devices that are beyond the reach of traditional wired LAN management techniques.
- The enemy within: Often the biggest threat to the security of your corporate systems and data are your own users, who disable security mechanisms and configurations in order to save a few seconds when logging in or synchronizing data. Protect and enforce system configurations by automatically identifying and correcting devices where users have defeated password protection by storing the password on the device, or changing security configuration options.
- Stay up-to-date: Mobile devices that send and receive data such as e-mail are just as susceptible to destructive viruses as desktop machines. However, it's difficult to get busy mobile workers to stop working long enough to download virus updates and security patches, especially on a slow connection. You require a management tool that will push out virus updates and security upgrades, and automate their installation without the need for user intervention.
- Gone, but not forgotten: Data encryption is not the only safeguard against unauthorized data access on lost devices. Fight back with your centralized management software by enabling a self-destruct policy that destroys confidential data on a lost device.
5. Protect your existing security investment
Whether you are creating new mobile applications or extending the reach of existing systems, your mobile deployment should be as secure as applications running on your corporate LAN. Integrate your mobile applications with existing security infrastructures through open standards and flexible architecture.
- Another brick in the firewall: Any mobile application should work with your current firewall, virtual private network (VPN), and PKI technology to integrate user authentication and permission functions with your existing systems. Browser-based communications between handheld devices and corporate systems should be encrypted using wireless transport layer security.
- Regardless of protocol: Your wireless application server technology should enable secure synchronization, encryption, and server-side authentication over whichever wireless protocol you choose.
- The e-mail of the species: E-mail is one of the most frequent points of entry for potential security threats, whether inside or outside the office. As you do with desktop e-mail systems, encrypt all incoming and outgoing messages between your corporate e-mail server and mobile devices that are outside your company's firewall. Your mobile mail application should also enforce password entry, and harmonize security configurations with LAN e-mail systems.
The bottom line
Security is about minimizing risk. This means identifying the weakest links in your system and then designing an appropriate solution that takes into account the associated risks and costs to protect your mobile data.
Has your company adequately secured employees' mobile devices? TalkBack below or e-mail us with your thoughts.
 |
 |
|
|
![]() |
|
[an error occurred while processing this directive] |
![]() |
 |
![]() |
[an error occurred while processing this directive]

|

|

[an error occurred while processing this directive]



|

|

|

|