Mobile Security Definition and Solutions

Mobile Security topics covering definition, objectives, systems and solutions.

PAGE 2

ABCs of Mobile Security (Page 2)

What security do mobile devices need?

Some mobile devices—particularly laptops—have a clear set of risks, since they are portable computers that can store valuable data and include applications that access your network and enterprise resources. A stolen laptop can be a treasure trove of critical data as well as an easy conduit into your enterprise’s systems. But other devices—PDAs, smart phones, iPods and USB “thumb drives,” for example—that seem innocuous can also expose your company’s data or provide outsiders access to your systems if not properly secured.

Some of these security threats are handled at the network level—such as requiring the use of authentication and VPNs for remote access into corporate systems—for PCs, laptops and handhelds alike. Some of these security threats are part of your client management tools, such as password policy enforcement and malware detection. But mobile devices typically need extra protection of the data they store, in the form of encryption, so a lost or stolen device can’t become a treasure trove for data thieves. (And most states require that companies report any loss of unencrypted data involving consumers’ private information, a disclosure that is not only costly to execute but even more expensive in terms of lost trust.) In some cases, mobile devices may need extra protection such as the use of hardware-based authentication tokens so a thief can’t access your enterprise network even if he discovers the user’s password.

For the mobile devices I do need, isn’t password protection sufficient?

Enforced password protection is a great first step, so if the devices are lost or stolen, they can’t easily be used. Be sure that all log-in settings require the user to type in a password—if the laptop or PDA logs itself in to your network, you’ll now have a significant breach potential. Be sure that the password is complex enough (at least eight characters, including a mix of numbers and letters) to resist hacking but not so difficult that users tape them to their devices. Also pay attention to how long a device may be idle before a password is required to use it again, suggests Paul Kocher, chief scientist for cryptography at technology consultant Cryptography Research. A long idle time will let someone walk away with a laptop at an airport or café and still have access to its contents, while a very short time-out period will require users to constantly enter their passwords, making them accessible to shoulder-surfers. A good rule of thumb is that two to five minutes of inactivity should trigger a password request.

If the data is particularly sensitive, you may want to use a second form of authorization—such as a smart card reader, fingerprint reader, SecurID token or challenge/response system—so that a thief needs more than a password to access the device. Note that this second-authentication strategy is more plausible on a laptop than on handheld devices such as PDAs, for which there are typically no such hardware tokens available.

But password protection (even when augmented with a second form of authentication) by itself won’t help secure the locally stored data. If a data thief removes the hard drive from a laptop, the data is easily opened from another computer.

Mobile

Loading...
Mobile MarketSpace
Tokenless Two-Factor Authentication In Action
Learn how this technology works, how to implement it, and compare it to other two-factor authentication solutions available on the market today. Learn more »
Mobile Security Landscape
This paper examines the current mobile security landscape, including myths surrounding the risks and threats, and how organizations can establish a solid mobile security strategy. Learn more »
Research: Microsoft Mobile Solutions
This paper compares the Research In Motion BlackBerry solution with the Microsoft(R) mobile solution by analyzing features of the user experience and the administrator experience. Learn more »
Five-Step Mobility Management Plan
This complimentary Aberdeen report details how best-in-class companies are using a 5-Step Mobility Management approach to take control of their burgeoning mobile infrastructures. A must read for IT executives looking to cut mobility TCO and support costs, reduce security risks and increase mobile user productivity Learn more »
Getting Started with LogMeIn Rescue
In this brief demo, you will see LogMeIn Rescue's key features and discover how they can help you support more users on PCs, Macs and smartphones, and solve more issues than ever before. Learn more »
Legacy Tools: Not Built for the Helpdesk
This paper explores the challenges of supporting this workforce with legacy tools such as RDP" and VNC" and identifies best practices that you can use to choose helpdesk tools. Learn more »
IT Supporting a Decentralized Organization
Learn the 5 best practices for remote IT support. Learn more »
It Pays to Provide High-Quality Support
Ceridian is a global organization that provides HR and payroll services to Fortune 500 businesses. See how Ceridian deployed remote IT support to reduce call center volume and improve customer support. Learn more »
 
SPONSORED LINKS
 

Mobile Security: The Essential Ingredient for Today's Enterprise

White Paper: Legacy Tools: Not Built for the Helpdesk

Learn how to maximize the mobile web opportunity

See how AT&T can help protect your network.

Webcast: Unleashing the Power of Customer Data

White Paper: Improve Agility with Operational Responsiveness

Taking a Seat at the Executive Table: The Reality of Virtualization

White Paper: Next Generation Remote Infrastructure Management

Keeping Your Members Safe from Online Scams and Predators

The Total Economic Impact of Network Security Intrusion Prevention

Join us at the US-Brazil IT-BPO Summit, on November 10th in New York.

Increase UPS efficiency without sacrificing protection.

Learn how advanced forecasting tools can deliver significant business results for global corporations.

Lower IT Costs with Oracle Database 11g Release 2

Ready to virtualize tier one applications? Check your virtualization maturity.

Seven Ways ITIL Can Help You in an Economic Downturn

Tips for successful virtualization management.

Unified Communications: Thoughts, Strategies and Predictions. Join the discussion

Read the RSA report: Security for Business Innovation

Webcast: Looking to the Cloud for Email and Collaboration Services

64-page prescriptive guide to security, compliance, and IT operations.

Keep your IT expertise up to date. Join the Intel Premier IT Professionals.

A Clear View Toward Virtualization

Virtualization Technology as a Business Solution

The rules of infrastructure management just changed.

White Paper: 5 Best Practices for Smartphone Support

Five-Step Mobility Management Plan

White Paper: Visibility and the New Normal of Mobile Work

White Paper: 4 Customer Service Myths

White Paper: Managed Security for a Not-So-Secure World

Global Research: CIOs Weigh In On Virtualization

5 Key Virtualization Management Challenges

Secure Email and Web-Based Communication from Evolving Attacks

WagerWorks Takes Fraudsters Out of the Game using iovation

Seven Design Requirements for Web 2.0 Threat Protection

Generation Remote Infrastructure Management - Changing the Paradigm

Cloud-Based Email Management: Opinion Shifts In Favor

eBook: How Can You Make Your People Productive Anywhere?

Achieving Business Agility with Application Grid

Taking the Service Desk to the Next Level

Learn about The Information Technology Infrastructure Library.

Top Five CIO Challenges

Streamline IT Costs. Boost Performance with WAN Optimization.

Want to know how you can maximize employee productivity?

Build your 1st app FREE with Force.com

TDWI checklist helps define data readiness for analytics. Download report.

A new fleet of PCs with a total ROI in 10 months. Find your ROI.

eZine: A Roadmap to Reducing IT Complexity

Reduce risk, gain agility. See how Progress can help your business.

Virtualization Technology as a Business Solution

 
 
RESOURCE CENTER