topics that matter; ideas worth sharing

share a tip, submit a link, add something new

Mobiles run riot in the absence of policy

June 7, 2005, 09:35 AM —  Computerworld Today — 

It's open slather for mobile devices in many enterprises where their usage and management is a policy-free zone.

An exclusive poll of Computerworld Australia readers showed that despite the significance of the corporate data mobile devices hold, very few IT managers had usage policies in place or a broader mobility strategy.

Only one in five organizations surveyed had introduced usage policies, which means users in many companies can literally walk out the door with the company's crown jewels.

Mobility strategies are a hit-and-miss affair, the Computerworld poll revealed, with most organizations practicing mobility but without policies to govern the use of a multitude of different devices.

University of Sydney team leader of enterprise systems Craig Hamilton runs a wireless network for notebooks and other devices, including Blackberries for senior executives.

And while Hamilton cited security as the most critical challenge in governing mobility, the university has no specific policy for use of the devices.

"We just have a general computer usage policy in place," Hamilton said, adding that because it is a university, IT has to be "fairly open" with mobility.

At Ausco Building Systems, the usage policy IT manager Ian Mascord enforces is based on cost, which is why mobile phones are covered but not Blackberries.

"It becomes a support nightmare if you let all different personal devices come in," Mascord said. "I think the main challenge with these sorts of devices is defining what you allow to access the network, what data gets transferred through the devices and what applications are used on them."

The mobility revolution may have caught many IT managers off guard, but IT director David Leong at law firm Arnold Bloch Leibler (ABL) has had a central policy since mobile devices were adopted to increase staff productivity and improve customer service.

"Mobility is an easy trap to fall into, because the barriers to entry aren't there anymore," Leong said.

The strategy, he said, should be about capitalizing on remote access and securing data.

"Our strategy is to have central control of the device," he said. "The Blackberry is good because of its security and central control and if someone has lost it we can delete the information remotely."

Leong said people taking company information out of the enterprise on mobile devices is the main problem, including e-mail, which may have sensitive information in attachments, downloaded to a notebook.

To prevent this, ABL's policy has been extended to notebooks where e-mail replication has been replaced with a Citrix environment so employees are no longer downloading information to public access points.

"Also, we use multifactor authentication, so if a notebook is lost you would need a token and password to access corporate systems," Leong said. "And we can kill a token."

Don't be too complacent with a mobile strategies, Leong says, as there are plenty of pitfalls and "you can easily fall into a trap."

"If you don't plan properly, you can invest in the wrong devices and have the wrong strategy," he said. "Consequently you can open up a list of problems for your organization; [for example] mobile viruses can potentially affect the whole enterprise."

Ben Dallenger, Puma Australia's information systems manager, says his organization has policies in place to govern mobility, including a specific security policy.

"We do have a few mobile devices, such as mobile phones and Trio Handsprings, [with] Lotus Notes on them," Dallenger said. "I think policies in this area are basically dictated by the technology advancements, especially wireless, and we'll move ahead as the technology does."

» posted by abennett

Computerworld Today

I like it!
Post a comment
The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.
Resources
White Paper

Symantec Backup Exec 12 and Backup Exec System Recovery 8 deliver industry leading Windows data protection and system recovery. Download this whitepaper to find out the top reasons to upgrade and how to get continuous data protection and complete system recovery.

Webcast

Data and system loss — from a hard drive failure, malicious attack, natural disaster, or simple human error — can happen anytime. Don’t leave your business vulnerable. Make sure you have a secure recovery strategy in place. Symantec's latest backup and system recovery technology can efficiently restore critical applications, individual emails and documents and even restore your entire system in minutes in the event of a loss.

White Paper

Businesses face a growing challenge to ensure that the IT environment is properly protected. Backup Exec 12 integrates with other applications in the Symantec family of products, to complement your current data protection strategy, keep your data securely backed up and make it recoverable when you need it most.

Free stuff
Featured Sponsor

Get a broad understanding of important regulations and how you can make sure your site is in adherence.





Learn how VeriSign SGC-enabled SSL Certificates can help improve site security and customer confidence in the free white paper, "How to Offer the Strongest SSL Encryption." In this paper you will learn the differences between weak and strong encryption and what they mean for your site's performance.

Get VeriSign's free white paper: "The Latest Advancements in SSL Technology" and learn about the benefits of strong SSL encryption, Extended Validation (EV) SSL and security trust marks and what these SSL offerings can do for your site.

Now with Extended Validation (EV) SSL available from VeriSign, you can show your customers that they can trust your site. Learn about EV SSL benefits in this free VeriSign white paper.

More Resources