byod and mobile security - boston universitybyod benefits improved productivity greater job...

20
BYOD AND MOBILE DEVICE SECURITY Ashish Jain, CIA IT Audit Manager Boston College 1

Upload: others

Post on 21-May-2020

3 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: BYOD and Mobile Security - Boston UniversityBYOD BENEFITS Improved productivity Greater job satisfaction Greater mobility (work and personal time) Saving for IT department from maintenance

BYOD AND MOBILE DEVICE SECURITY

Ashish Jain, CIA

IT Audit Manager

Boston College 1

Page 2: BYOD and Mobile Security - Boston UniversityBYOD BENEFITS Improved productivity Greater job satisfaction Greater mobility (work and personal time) Saving for IT department from maintenance

AGENDA

BYOD benefits

Threats to mobile devices

Threat causes

Why we are concerned?

What are the challenges?

BC approach

Best practices and solutions

Policy considerations

Audit perspective

2

Page 3: BYOD and Mobile Security - Boston UniversityBYOD BENEFITS Improved productivity Greater job satisfaction Greater mobility (work and personal time) Saving for IT department from maintenance

MOBILITY IS PERVASIVE

Around 44% of knowledge workers telecommute at least once a week

78% of white-collar employees use a mobile device for work

Average # of connected devices will increase from 2.8 to 3.3 by 2014

50% noted that their organization is implementing a desktop virtualization strategy

3

Source: Cisco IBSG 2012 Survey

Knowledge workers – who uses knowledge at work Picture source: theboldsoul.lisataylorhuff.com

Page 4: BYOD and Mobile Security - Boston UniversityBYOD BENEFITS Improved productivity Greater job satisfaction Greater mobility (work and personal time) Saving for IT department from maintenance

BYOD BENEFITS

Improved productivity

Greater job satisfaction

Greater mobility (work and personal time)

Saving for IT department from maintenance and support load

Opportunities for desktop virtualization

4

Pictures: zboostyourbusiness.com and

leveltendesign.com

Page 5: BYOD and Mobile Security - Boston UniversityBYOD BENEFITS Improved productivity Greater job satisfaction Greater mobility (work and personal time) Saving for IT department from maintenance

IPAD USE

5

Source: CIRP’s surveys of 1,000 consumers. New iPads in Dec 2011- April

2012.

Page 6: BYOD and Mobile Security - Boston UniversityBYOD BENEFITS Improved productivity Greater job satisfaction Greater mobility (work and personal time) Saving for IT department from maintenance

TOP THREATS TO MOBILE DEVICES

Loss or theft of device

Phishing

Malware and viruses

Spyware

Worms

Spoofing

6

Page 7: BYOD and Mobile Security - Boston UniversityBYOD BENEFITS Improved productivity Greater job satisfaction Greater mobility (work and personal time) Saving for IT department from maintenance

WHAT IS AT STAKE?

Loss of confidential data, e.g., SSNs, personal

and student information such as grades, credit

card, and account numbers.

Intellectual property, e.g., inventions

Research data

Business confidential, e.g., alumni information

7

Page 8: BYOD and Mobile Security - Boston UniversityBYOD BENEFITS Improved productivity Greater job satisfaction Greater mobility (work and personal time) Saving for IT department from maintenance

CAUSES

Lack of policies and procedures for mobile

devices

Difficult to enforce policies and procedures

Educational environment

Personally owned device

Most don’t know all sources of confidential

data and who has this kind of information

Lack of initiatives and authority

8

Page 9: BYOD and Mobile Security - Boston UniversityBYOD BENEFITS Improved productivity Greater job satisfaction Greater mobility (work and personal time) Saving for IT department from maintenance

CHALLENGES

Who owns data on mobile devices and is

there a strategy to get it back?

Do you have authority to put in place desired

policies and procedures?

Do you have list of approved apps?

What is your malware and antivirus strategy?

Have you identified what really needs to be

secured?

9

Page 10: BYOD and Mobile Security - Boston UniversityBYOD BENEFITS Improved productivity Greater job satisfaction Greater mobility (work and personal time) Saving for IT department from maintenance

CHALLENGES

Understanding what users do and want

How to enforce password?

What is your strategy if device is lost or stolen?

Difficulties in reviewing and understanding

voluminous amounts of log data

How to ensure that devices are updated to

latest firmware?

10

Page 11: BYOD and Mobile Security - Boston UniversityBYOD BENEFITS Improved productivity Greater job satisfaction Greater mobility (work and personal time) Saving for IT department from maintenance

Developing an

Approach for Mobile

Device Security

11

Page 12: BYOD and Mobile Security - Boston UniversityBYOD BENEFITS Improved productivity Greater job satisfaction Greater mobility (work and personal time) Saving for IT department from maintenance

THINGS TO CONSIDER

Understand what users want

Only minimal headache

Security for their personal data

What do we really need to secure?

Cost vs. benefit analysis

Various layers of security

12

Page 13: BYOD and Mobile Security - Boston UniversityBYOD BENEFITS Improved productivity Greater job satisfaction Greater mobility (work and personal time) Saving for IT department from maintenance

OUR APPROACH

Device activation is required and MAC address

is stored.

If issues are found,

deactivate or isolate the device

limit access where device does not have access to

data (manual process).

13

Page 14: BYOD and Mobile Security - Boston UniversityBYOD BENEFITS Improved productivity Greater job satisfaction Greater mobility (work and personal time) Saving for IT department from maintenance

BEST PRACTICES

Risk management and policies

Track MAC address

User authentication at every login

Clean devices periodically and at disposal

VPN use or remote log-in

Web-based access

Use log data for your leverage; analyze log data

to identify patterns or suspicious activity

14

Page 15: BYOD and Mobile Security - Boston UniversityBYOD BENEFITS Improved productivity Greater job satisfaction Greater mobility (work and personal time) Saving for IT department from maintenance

POLICY CONSIDERATIONS

Password or pin

Remote wipe or may be remote disable

Restrict “jailbroken” or “rooted” devices

List of apps to avoid

Make recommendations on device selection

Mobile data protection (MDP), network access control (NAC), and mobile device management (MDM)

Support structure for mobile devices

Malware, virus, spyware protection

15

Page 16: BYOD and Mobile Security - Boston UniversityBYOD BENEFITS Improved productivity Greater job satisfaction Greater mobility (work and personal time) Saving for IT department from maintenance

AUDIT CONSIDERATIONS

Risk-based approach. Common topics:

Risk management and security policy

Device management and tracking (remote

wipe, device provisioning and deprovisioning)

Access Controls (authentication, ports,

separate process based on data on the device)

Data Security (encryption, data retention, and

data transfer)

16

Page 17: BYOD and Mobile Security - Boston UniversityBYOD BENEFITS Improved productivity Greater job satisfaction Greater mobility (work and personal time) Saving for IT department from maintenance

AUDIT CONSIDERATIONS

Malware and virus protection

Secure transmission (VPN, Internet Protocol Security)

Employee awareness and training

Foreign device authorization and authentication process

Monitoring of logs

Problem identification and resolution procedures

17

Page 18: BYOD and Mobile Security - Boston UniversityBYOD BENEFITS Improved productivity Greater job satisfaction Greater mobility (work and personal time) Saving for IT department from maintenance

WRAP-UP

18 Source: modernanalyst.com

Source: cloudtweaks.com

Page 19: BYOD and Mobile Security - Boston UniversityBYOD BENEFITS Improved productivity Greater job satisfaction Greater mobility (work and personal time) Saving for IT department from maintenance

Questions?

19

Page 20: BYOD and Mobile Security - Boston UniversityBYOD BENEFITS Improved productivity Greater job satisfaction Greater mobility (work and personal time) Saving for IT department from maintenance

CONTACT INFORMATION

Ashish Jain, CIA

IT Audit Manager

Boston College

[email protected]

617-552-4336

20