Share

Top 5 Stories

News

One in five firms have no policy regarding personal mobile device use at work

29 July 2011

More than one out of five organizations do not have a security policy governing the use of personal mobile devices at work, even though two out of three said they allow personal mobile devices on the corporate network, according to a survey by Courion.

This lack of a security policy has led to situation in which one in 10 organizations has had a data breach following the loss of a personal mobile device that had access to the network, according to a survey of 988 IT decision makers at large organizations by Courion, a provider of identity and access management products.

“Pretty much all organizations are allowing some type of remote access to their systems from mobile devices”, said Dave Fowler, senior vice president of products and marketing at Courion.

“If a personal device is lost, the question becomes, what can the company do to respond to that lost device to ensure that it is protected if there is company information on that device, or if that device has the ability to access their systems? What we found was that in lot of cases, the organization did not have a policy and therefore did not know how to respond when a device was lost”, Fowler told Infosecurity.

In addition, 57% of respondents were confident that they could control access to resources on their corporate network. That number dropped to 34% when asked about cloud access, and 40% when handling employee access via mobile devices and laptops.

“Companies feel good about protecting their assets inside their organization, but less so from outside their organizations, even though there are a growing number of people using mobile devices to access company assets from outside the organization”, Fowler said.

“Not all risks are created equal. What I have access to might not be the same as what other people have access to. Knowing the risks posed by the loss of a device by a certain individual helps the organization determine how quickly it needs to respond, how important it is to take action, and what action to take”, he added.

Asked how they would respond to a lost mobile device, 55% of respondents said they would wipe the device.

“From the company perspective, in order to be able to protect themselves they have to be able to take action to protect whatever company information is on that handheld”, Fowler noted. From a policy perspective, organizations should inform their employees that if they use personal devices to access corporate information and the device is lost, personal information along with corporate information will be wiped, he added.

Courion recommends that organizations implement and manage a comprehensive access strategy in order to define, assess, enforce, and verify that the right users have the right access to the right resources. Ensuring that employee and contractor identities are matched with the access rights they are given – regardless of device or location – is important to securing corporate data, the company said.

This article is featured in:
Compliance and Policy  • Data Loss  • Identity and Access Management  • Wireless and Mobile Security

 

Comments

Jennm says:

02 August 2011
My company offers a mobile security policy available for free download from our website. It's a great resource for anyone who needs a mobile security policy. http://bit.ly/ifCVLd

Note: The majority of comments posted are created by members of the public. The views expressed are theirs and unless specifically stated are not those Elsevier Ltd. We are not responsible for any content posted by members of the public or content of any third party sites that are accessible through this site. Any links to third party websites from this website do not amount to any endorsement of that site by the Elsevier Ltd and any use of that site by you is at your own risk. For further information, please refer to our Terms & Conditions.

Comment on this article

You must be registered and logged in to leave a comment about this article.