Have a blanket approach to security by owning every mobile device that leaves your office and make access control and encryption mandatory. DO NOT allow users to use their own mobile device to store company information. Don’t be fooled into believing that they are already protecting their devices with the “factory” password settings or encryption. Nine times out of 10 they won’t be. Record the serial numbers of all PDAs and similar devices including memory cards.
Golden Rule Number Five:
Be realistic with passwords – Users hate them! An enforced, long and difficult, password will result in them writing it down or forgetting it. If they can choose themselves, they will pick the easiest passwords they can such as their pet or child’s name, anniversaries or birthdays. You bet after a long Christmas holiday or annual leave they’ll make a call to the helpdesk to ask for a reset. One way around this is to dispense with the idea of passwords altogether. Pointsec has, for example, presented a new idea with their PicturePIN access control which consists of a series of pictures chosen by the user from a, randomly displayed, larger gallery. Instead of having to remember a password in order to access his encrypted information, the user simply points out the pictures corresponding to “his” story. Not only is this system just as secure as traditional passwords, but there are other advantages too. Its novel, so there’s more chance that people will want to use it. Plus, visual images are much harder to forget than faces. There is even a possibility to add your own pictures for your organisation. And just in case the user is tempted to write down his “password”, he’ll find it very difficult to do so.
So the thief who steals a machine and expects to find the password for the encrypted drive written on the base of the device is going to be sadly disappointed.
Golden Rule Number Six:
Become a realist – but still endeavour to educate your users! Accept the fact that users won’t take a blind piece of notice of security, however, don’t give up – send them a mobile security use policy – make them sign and return it by getting HR to work this policy into their appraisals. Try and make them streetwise but accept that they will still leave their mobile devices in the car, in airports and have them pick-pocketed in
Nothing can be guaranteed, but by following these rules, you can show that you have taken adequate steps to protect your organisations information and hopefully rest at night, safe in the knowledge that when thousands of mobile devices get lost or stolen this year, yours won’t be the one hitting the papers with embarrassing and expensive consequences.