Bring Your Own Device (BYOD) is becoming the rule rather than the exception in today’s workplace. Although BYOD may be a convenience to your employees, you need to think about its impact on corporate security models. This article explains how you can adopt BYOD in your workplace while protecting secure data.
New technology brings more ways to access data, new types of devices and alternatives to the traditional PC platform. Apple CEO Tim Cook appropriately called this the “post-PC era.” These dynamics have created a shift toward BYOD that encompasses more than personal computers. It means employees using smartphones, tablets, BlackBerrys, ultralight books and more for their work. The concept of BYOD broadens to include software and services, as employees use cloud services and other tools on the web. The shortcomings of technology which made BYOD unrealistic a few years ago have given way to broad popularity and use of these tools.
Failing to respond to users’ demand introduces a risk that enterprising users will find insecure workarounds. Far better to accept some well-considered risk than find out vital data has escaped via the CEO’s webmail account. Unfortunately at first glance options are not very palatable – the traditional centralised approach towards configuration management, software, patching and AV is often not possible, or even relevant, on these platforms.
The simple question, “What exactly does the staff want to do?” may suddenly make the issue easier to deal with. Chances are the base requirements are relatively simple – nobody is planning to ditch their laptop quite yet so your users probably don’t need, or want, access to the scary stuff. In fact, the answer will probably start with two things: email and web browsing.
Here are some practical polices and points to educate the staff on BOYD.
1. Always secure devices with a password
One of the most basic security tips, but one which is sometimes completely overlooked! Having no access protection at all is unwise. Swipe patterns are ok, but greasy finger-trails could reveal too much. A four-digit PIN is an improvement but using a strong passcode is the ideal protection.
2. Ensure that the device locks itself automatically
If password-protection is setup on a device but then left unlocked on the desk for 15 minutes, it won’t achieve very much. Most devices automatically lock themselves after a period of inactivity, recommend shortest timeout as long as the staff is comfortable. Two to five minutes is better than ten to thirty, even if it does feel slightly inconvenient.
3. Install security software
Tablets and smartphones are computing devices and should be protected accordingly. Look for an app like Sophos Mobile Security that includes malware prevention, remote data wipe, privacy review of apps and an automatic security advisor to alert of potential risks when device settings are changed. Sophos Mobile Control is a good device management solution for securing organisation’s phones and tablets.
4. Only allow apps downloads from approved sources
The Google Play Store and Apple’s App Store take security pretty seriously and are very careful about what apps they make available and will withdraw apps that raise concerns after release.
5. Check apps’ permissions
Many apps require more than the basic default permissions. For instance, you can reasonably expect an SMS app to send and receive text messages just as a mapping app will request your GPS location.
But something like a calculator that needs network access or an alarm clock that wants to read your contact database should be treated with extreme caution!
6. Don’t miss operating system updates
Updates to OS often include system vulnerability patches, so it is important to install them.
End-users might want to be advised of updates rather than having them automatically installed, as early adopters sometimes experience teething problems – but the forgetful may prefer that to missing updates altogether.
7. Links received via email or text must be treated with caution
Since emails can be picked up on smartphones, clicking on links should be exercised with caution. Phishing scams are not limited to email – a text message can incite users to click on a dodgy link or ask for personal information. Even simply replying to unknown SMS or email senders can raise the crooks’ interest, leading to more pressure to respond.
8. Encrypt Devices
Even password protected devices are vulnerable; a thief could still plug your device into a computer and gain access to all of information saved on the device that usually include personal details. Using encryption on your smartphone can help to prevent such data theft.
9. Turn off automatic Wi-Fi connection
One of the great things about modern mobile phones is their ability to connect to the internet in many ways, but continually probing for wireless networks gives away information about your identity and location, and blindly connecting to unencrypted access points can let phone leak all sorts of useful things for malicious actors to intercept and act upon.
So, telling the devices to “forget networks” no longer use to minimise the amount of data leakage and configure automatic turn on/off wireless in certain places using a location-aware smartphone app.
10. Turn off Bluetooth and NFC when not in use
Bluetooth and NFC (near field communication) are great in terms of connectivity, allowing use of accessories such as wireless keyboards and headsets or make payments with a wave of smartphone. But it does open a door for the bad guys to gain unauthorised access to device and access the data, so these features should be switched off or put device into “not discoverable” mode whenever possible. When pairing devices, never accept requests from unknown devices.
