Latest news
The Cloud Security Alliance (CSA) Mobile Working Group released a research report identifying 17 key elements that are critical for organizations to consider for the full lifecycle security management of mobile devices.With the growth in the number of applications, content and data being accessed through a variety of devices, mobile device management (MDM) has to extend beyond device management alone. As IT departments are now fully responsible for company-owned devices, organization must look to adopt policies and practices to prevent any compromise in security.
Most important, the report cites, is for organizations to include a system-centric functionality to secure and manage data and applications, as well as information-centric functionality such as the delivery of the enterprise application store or content library.
“Mobile devices are becoming an integral part of corporate networks and as employees are increasingly using their personal device to access cloud-based applications and services, identity management is paramount in ensuring that this access remains secure,” said Patrick Harding, CTO, Ping Identity. “By having the right identity management processes, enterprises can provide employees with secure and convenient access to cloud apps via single sign-on from mobile devices - whether BYOD or not. The CSA has taken important steps in identifying the key elements organizations need to consider before adopting a BYOD policy and we’re happy to see identity management recognized as a key piece.”
While every company will have a different tolerance for risk and will adopt mobile technology in different ways, there are several fundamental components of MDM that have to be considered and incorporated into policy and practice. With each component falling into one of three major categories: software and hardware, inventory and security, the report provides implementation best practices as well as potentials risks along with a ‘Must Have’ or ‘Optional” rating to help organizations better prioritize their security efforts.
Key components to MDM identified include:
- Policy
- Risk Management
- Device Diversity/Degree of Freedom
- Configuration Management
- Software Distribution
- Enterprise AppStore
- Content Library
- Procurement
- Provisioning
- Device Policy Compliance and Enforcement
- Enterprise Activation/Deactivation
- Enterprise Asset Disposition
- Process Automation
- User Activity Logging/Workplace Monitoring
- Security Settings
- Selective Wipe/Remote Wipe/Lock
- Identity Management/Authentication/Encryption.


Spotlight

The CSO perspective on healthcare security and compliance
Posted on 20 May 2013. | Randall Gamby is the CSO of the Medicaid Information Service Center of New York. In this interview he discusses healthcare security and compliance challenges and offers a variety of tips.

Cyber espionage campaign uses professionally-made malware
Posted on 20 May 2013. | A massive cyber espionage campaign has been hitting government ministries, IT companies, academic research institutions, and more.

Ransomware adds password stealing to its arsenal
Posted on 17 May 2013. | Microsoft researchers are warning about a new variant of the well-known Reveton ransomware doing rounds.

IT security jobs: What's in demand and how to meet it
Posted on 15 May 2013. | Let's say you want a career in information security, where do you start? What credentials do you need? What are employers looking for? Read on to find some answers.

Hacking charge stations for electric cars
Posted on 15 May 2013. | Ofer Shezaf talks about what charge stations really are, why they have to be ‘smart’ and the potential risks created to the grid, to the car and most importantly to its owner’s privacy and safety.
By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.





