Editorial & Analysis
Popular
Technology Categories
- Security (280)
- Desktop Virtualization (235)
- Uncategorised (226)
- Public/Private clouds (222)
- Applications (218)
- Business Continuity (215)
- Server Virtualization (191)
- BYOD (189)
- Network Virtualization (182)
- Storage Virtualization (169)
- Big Data (155)
- Availability (149)
- Network Perfomance Management & Monitoring (145)
- Archiving & Back-Up (136)
- Consolidation (128)
- Wireless LAN (122)
- Performance Management (119)
- Systems Management (119)
- Software as a Service (SaaS) (114)
- Infrastructure as a Service (IaaS) (112)
- Network Capacity Planning & Management (112)
- Hosted solutions / applications (111)
- Network equipment, Repeaters, Hubs, Bridges, Switches, Routers (110)
- Governance, Risk & Compliance (104)
- Data Deduplication (103)
- Servers/Hardware (95)
- Mobile Security (92)
- Capacity Management (90)
- Virtualization Security (90)
- IP Convergence (90)
- Storage as a Service (87)
- Storage Networking – IP storage,Infiniband & iSCSi (86)
- Storage Area Networking (SAN) (86)
- Application Delivery Network (86)
- Disk Storage, Flash, SSD, Optical (85)
- Business Intelligence (82)
- Unified Communications (78)
- Wireless Security (77)
- Automation (77)
- Energy Efficiency (76)
- Enterprise Mobility Management (73)
- Flexible & Smarter Working (70)
- Mobile Device Management (70)
- Risk Management (68)
- Campus Networks (67)
- Recovery (65)
- Design & Build (64)
- Platform as a Service (PaaS) (63)
- Managed Security Services (60)
- Content Monitoring/Filtering (56)
- Risk Analysis (54)
- Identity & Network Access Control/Management (52)
- Managed Network Security Services (50)
- Business Impact Analysis (49)
- Managed Hosting (49)
- Email Archiving & Management (49)
- Smartphones/Tablets (49)
- Enterprise Content & Document Management (46)
- Storage Resource Management (SRM) (46)
- Collaboration Tools/Applications (44)
- Fibre Channel over Ethernet FCoE) (43)
- Mobile Enterprise Applications (43)
- Network Attached Storage / NAS (43)
- Cabling (41)
- Mobile Platforms (41)
- IPv6 (40)
- Penetration Testing/Risk & Vulnerability Assessment (38)
- Information Lifecycle Management (ILM) (38)
- Thin Provisioning (38)
- Workflow & Process (36)
- Load Balancing (36)
- Optical Networks (35)
- Forensics (34)
- E-Discovery (30)
- Regulation & legislation (30)
- IP Telephony (30)
- VPN/SSL (29)
- Unified Threat Management (29)
- Power & Protection (29)
- Communications-Enabled Business Process (27)
- Tape Storage (27)
- ISP's (26)
- Enterprise Search & retrieval (24)
- HPC (23)
- Video/Web Conferencing (22)
- Metropolitan Networks (22)
- Mesh Networks (21)
- Collaborative Communications servers (Exchange etc) (20)
- Encryption/PKI/Digital Certificates (20)
- Field Services (17)
- Audio Conferencing (16)
- IP PBX (16)
- Transparency (15)
- Openflow/Software Defined Networking (14)
- Classification (14)
- Risk frameworks (11)
- Instant Messaging (11)
- Wireless Expense Management (11)
- Fixed Mobile Convergence (10)
- Data Masking (9)
- SIP Trunking (8)
- Social Software (7)
- Data Erasure (6)
- Presence (6)
- BS25999 (5)
- HVAC (5)
Popular Categories
Securing mobile data: an increasingly complex challenge
22 Nov 2011
The Information Commissioner's Office (ICO) last week came down hard on two UK charities for failing to encrypt personal data held on laptops - but as Jessica Twentyman argues, most organisations need to consider encrypting employees' smartphones and tablet computers, too.
| Last week, the Information Commissioner's Office (ICO) named and shamed two charities for breaching the Data Protection Act. The ICO said that Sheffield-based Aperger's Children and Carers Together (ACCT) and Nottingham-based Wheelbase Motor Project both had unencrypted data stolen, including highly sensitive information relating to vulnerable young people. |
Commenting on the cases, the ICO's acting head of enforcement Sally-Anne Poole said: "The ICO's guidance is clear - any organisation that stores personal information on a laptop or other portable device must make sure that the information is encrypted." The ICO also freely provides guidance to UK companies on its own approach to encryption.
So why is the message not getting through? It's possible that, within charities, there's a feeling that money could be better spent elsewhere, on the organisation's most pressing projects and current campaigns, or simply a lack of in-house expertise to deploy encryption.
But while the ICO has decided not to fine the two charities involved for their non-compliance, it has not held back from holding them up as examples of poor practice. The bosses of both charities have each had to sign an agreement confirming that, in future, their organisations will encrypt all portable and mobile devices used to store sensitive personal information and update their policies and procedures for the storage and use of personal data.
Regardless of the sector in which an organisation operates, the law is the law. But for many companies, it's not just laptops and USB sticks and hard drives they need to worry about encrypting these days - it's the smartphones and tablet computers that employees are buying themselves and bringing to work.
According to Chenxi Wang, an analyst with IT market research company Forrester Research, the increasing use of personal mobile devices in the workplace is posing some increasingly complex security challenges.
In a recent report, Managing the Security and Risk Challenges of Personal Devices in the Workplace, Wang identifies four major data security risks from the use of personal mobile devices.
First, there is the risk of device theft or loss. “From the corporate perspective, device loss could lead to data compromises if sensitive data lives on the device”, the report says.
Second, the mobility and portability of these devices increase the threats to data protection. “To defend against casual data access, you can implement PIN-based entry and device lock. To protect against active attacks, you will need measures like full disk or file encryption”, writes Wang.
Third, she warns, there's the risk of attack from a malicious, but authorised, insider: “If you are concerned with employee misuse or malicious insider threats, encryption alone does not do the job. You need to actively restrict data manipulation operations like cut-and-paste and control which mobile apps can handle the corporate data.”
Finally, data-stealing malware is increasingly attacking mobile devices. Any personal device with the freedom to download mobile apps is a ripe target for infection, she says.
The challenge for IT teams, says Wang, lies in balancing corporate security measures with an employee's freedom to use their device as they choose. "Secure processes such as remote wipe, pin-based entry and centralised management will satisfy many of the security requirements of your organisation. However, when the mobile actions of a user conflict with the interests of the enterprise, this raises notable legal issues surrounding the adoption of personal devices in the workplace."
In other words, it's going to take a company-wide effort to establish a robust mobile policy, one that balances the security requirements of the enterprise with the user's own device experience. Encrypting laptops is just the tip of the iceberg - but it's clearly a must-have for any UK organisation handling personal data that wishes to avoid the censure of the ICO.

