Find White Papers
Home
About Us
List Your Papers
    
> Pointsec > Enterprise Security for Mobile Computing Devices

Enterprise Security for Mobile Computing Devices

White Paper Published By: Pointsec

This paper will help security officers and staff of large organizations seeking to protect sensitive data on mobile computing devices.



Tags : 
wireless security, network security, laptop security, mobile computing, secure mobile, data protection, access control, vulnerability management

Pointsec
Published:  Aug 21, 2009
Type:  White Paper
Length:  11 pages


ENTERPRISE SECURITY FOR MOBILE COMPUTING DEVICES
Abstract Enterprise security plans must now assure the protection of data residing on mobile computing devices. But the inherent lack of physical access controls on mobile devices creates special challenges that must be resolved to provide effective and practical security. This paper will help security officers and staff of large organizations seeking to protect sensitive data on mobile computing devices.
Executive Summary Mobile computing devices such as notebook PCs, PDAs and smart phones have become an indispensable part of the modern enterprise. Unfortunately, the very portability that makes these devices attractive greatly increases the risk of exposing confidential data, of allowing network penetration, and of "importing" infections inside the network. The core problem is that the majority of mobile devices lack the physical and electronic access controls necessary to maintain security in non-secure environments. As a consequence, data stored on mobile devices is much more "at risk" than transmitted data. User-controlled authentication and discretionary file encryption cannot provide sufficient or dependable security for enterprises. Only security products that combine enforceable, mandatory access control and automatic encryption provide the foundation for securing mobile devices. But even these mechanisms are not sufficient; in an enterprise setting, a special security infrastructure is required to deploy and maintain the security regime on multiple types of devices regardless of location. Pointsec security products offer the physical and electronic access control features essential for securing mobile devices, and the infrastructure necessary for enterprise usage.
Mobile computing devices have become part of the enterprise information and security infrastructure Seemingly endless numbers of mobile computing devices are being deployed by organizations as a primary or auxiliary work platform. A wide range of machines including notebook PCs, tablets, handhelds, PDAs and smart-phones are used for production, not just reference, in a growing array of applications. This important trend is driven by pressures to reduce operating costs, improve service, and create greater flexibility. Less obvious is the fact that mobile devices increasingly contain the most confidential and valuable information found in many organizations; in fact, one study indicates that about two-thirds of "fresh and critical business data" resides on employee 1workstations, not on servers. Proprietary company files, passwords, user credentials, and logon scripts are frequently found on mobile computers. Company email stored on portable PCs and Web-enabled cell phones can also contain sensitive information.
? Copyright 2002 Pointsec Mobile Technologies, Inc. All rights reserved Page 1 of 11 ENTERPRISE SECURITY FOR MOBILE COMPUTING DEVICES
Even without special security issues, the sheer number of mobile devices being deployed forces organizations of all sizes to consider the protection of data on mobile devices as an essential part of enterprise security planning. Ultimately this means that mobile device security must be of sufficient strength and sophistication to enforce and support corporate security policy. The crucial test is whether a given piece of data can reside as securely on a mobile device in a public place as it would on a desktop device within the company security perimeter. The realization that mobile device security is a permanent enterprise security issue leads to the conclusion that it cannot be viewed as an "add-on" expense any more than door locks can be considered an optional feature of a building. The real issue is not ROI but prudent management of vital corporate resources. When viewed from the enterprise standpoint, the general requirements of mobile computer security become clear. The security mechanism must: i) Protect confidential data at a specific level of security as defined by company policy ii) Be scalable, easily deployable, and very robust iii) Not inconvenience or deter users or impair machine performance iv) Enable the organization to comply with applicable Federal regulations that mandate information security such as the Health Insurance and Accountability Act (HIPAA) governing health care organizations, and the Gram-Leach-Bliley Act (GLBA) pertaining to financial institutions v) Pr... [download for more]

Browse Technology Topics

Data Center

Virtualization, Cloud Computing, Infrastructure, Design and Facilities, Power and Cooling, Green Computing  
    

Data Management

Application Integration, Analytical Applications, Business Intelligence, Configuration Management, Database Development, Data Integration, Data Mining, Data Protection, Data Quality, Data Replication, Database Security, EDI, SOAP, Service Oriented Architecture, Web Service Management, Data Warehousing  
    

Enterprise Applications

Application Integration, Application Performance Management, Best Practices, Business Activity Monitoring, Business Analytics, Business Integration, Business Intelligence, Business Management, Business Metrics, Business Process Automation, Business Process Management, Call Center Management, Call Center Software, Change Management, Corporate Governance, Customer Interaction Service, Customer Relationship Management, Customer Satisfaction, Customer Service, EBusiness, Enterprise Resource Planning, Enterprise Software, EProcurement, Extranets, Groupware Workflow, HIPAA Compliance, IP Faxing, IT Spending, Marketing Automation, Performance Testing, Product Lifecycle Management, Project Management, Return On Investment, Risk Management, Sales & Marketing Software, Sales Automation, Server Virtualization, Simulation Software, Supply Chain Management, System Management Software, Total Cost of Ownership, Video Conferencing, Voice Recognition, Voice Over IP, Workforce Management, Incentive Compensation, Spend Management, Manufacturing Execution Systems, International Computing  

Human Resource Technology

Human Resources Services, Payroll Software, Time and Attendance Software, Workforce Management Software, Financial Management, Employee Monitoring Software, Employee Training Software, Recruiting Software/Services, Employee Performance Management, ELearning, Benefits Management, Expense Management  
    

IT Career Advancement

Cisco Certification, Microsoft Certification, Linux Certification, Network Security Certification, Software Development Certification  

IT Management

Employee Performance, ITIL, Productivity, Project Management, Software Compliance, Sarbanes Oxley Compliance, Service Management, Desktop Management  
    

Knowledge Management

Collaboration, Collaborative Commerce, Contact Management, Content Delivery, Content Integration, Content Management System, Corporate Portals, Customer Experience Management, Document Management, Information Management, Intranets, Messaging, Records Management, Search And Retrieval, Search Engines, Secure Content Management, SLA  

Networking

Active Directory, Bandwidth Management, Convergence, Distributed Computing, Ethernet Networking, Fibre Channel, Gigabit Networking, Governance, Grid Computing, Infrastructure, Internetworking Hardware, Interoperability, IP Networks, IP Telephony, Local Area Networking, Load Balancing, Migration, Monitoring, Network Architecture, Network Management, Network Performance, Network Performance Management, Network Provisioning, Network Security, OLAP, Optical Networking, Quality Of Service, Remote Access, Remote Network Management, Server Hardware, Servers, Small Business Networks, TCP/IP Protocol, Test And Measurement, Traffic Management, Tunneling, Utility Computing, VPN, Wide Area Networks, Green Computing, Cloud Computing, Power and Cooling, Data Center Design and Management, Colocation and Web Hosting  
    

Platforms

AS/400, Domino, Linux, Microsoft Exchange, Oracle, PeopleSoft, SAP, Siebel, Solaris, Tivoli, Unix, Web Sphere, Windows, Windows Server  

Security

Access Control, Anti Spam, Anti Spyware, Anti Virus, Application Security, Auditing, Authentication, Biometrics, Business Continuity, Compliance, DDoS, Disaster Recovery, Email Security, Encryption, Firewalls, Hacker Detection, High Availability, Identity Management, Internet Security, Intrusion Detection, Intrusion Prevention, IPSec, Network Security Appliance, Password Management, Patch Management, Phishing, PKI, Policy Based Management, Security Management, Security Policies, Single Sign On, SSL, Secure Instant Messaging, Web Service Security, PCI Compliance, Vulnerability Management  
    

Software Development

.NET, C++, Database Development, Java, Middleware, Open Source, Software Outsourcing, Quality Assurance, Scripting, SOAP, Software Testing, Visual Basic, Web Development, Web Services, Web Service Security, XML  

Storage

Backup And Recovery, Blade Servers, Clustering, IP Storage, ISCSI, Network Attached Storage, RAID, Storage Area Networks, Storage Management, Storage Virtualization, Email Archiving, Data Deduplication  
    

Wireless

802.11, Bluetooth, CDMA, GPS, Mobile Computing, Mobile Data Systems, Mobile Workers, PDA, RFID, Smart Phones, WiFi, Wireless Application Software, Wireless Communications, Wireless Hardware, Wireless Infrastructure, Wireless Messaging, Wireless Phones, Wireless Security, Wireless Service Providers, WLAN  
Search