IT Leaders Grapple With Ways To Manage The Risk,: As Mobile Devices Continue To Flood Into The Enterprise
IT Leaders Grapple With Ways To Manage The Risk,: As Mobile Devices Continue To Flood Into The Enterprise
IT Leaders Grapple With Ways To Manage The Risk,: As Mobile Devices Continue To Flood Into The Enterprise
As mobile devices continue to flood into the enterprise, IT leaders grapple with ways to manage the risk, BYBOB VIOUNO
or a small one, for that matter chances ,:';/ are good that you're seeing a steady rise in 'fXy the number of employees using smartK; phones and tablets at work. AS; The upside of this trend is that people might be more productive if they're using mobile devices they're comfortable with to access corporate data, collaborate with colleagues and communicate with customers. But increased mobility comes with risks. Smart IT executives are mapping out strategies for managing their organizations' mobile risks and benefits. More than half (52%) of the 334 IT executives who responded to Computerworld^ 2013 Forecast survey said they're ramping up mobile risk management efforts, and more than one-third (38%) said they're seeking help from outside providers. Yet the results also show that many organizations haven't yet adopted a formal mobile device management strategy. Only 46% of the respondents said they have such a plan in place. Those companies that have launched mobile strategies are getting a handle on the risks. Chicopee Savings Bank in Chicopee, Mass., with seven branches in western Massachusetts, began deploying Windows smartphones about five years ago and has since moved to Android devices. "We initially deployed these devices to meet the business need of keeping corporate email, contacts and calendaring continually available to a small subset of our executive, sales and support employees whether they were in or out of the office," says Darlene Libiszewski, senior vice president of IT. The bank launched an assessment to identify the risks and benefits of mobile devices. "A formal risk management discipline has always driven where we invest our resources," Libiszewski says. Confidential information residing on mobile devices was among the security risks. "To minimize the risk effectively, we realized we needed to own the device to implement and manage the controls," she says. But to minimize the cost of deploying smartphones, the bank is now considering adopting a bring-your-own-device (BYOD) program.
C0MPUTERW0RLD.COM
31
FORECAST 2013
Managing risk is an ongoing process, Libiszewski says. "But I would say that more risk management focus has been placed in the mobile space because it is developing so rapidly and customer adoption is huge and face it, this space is the new frontier to be exploited," she adds.
I Disagree:
devices if necessary. Only individuals in the company who require access to corporate email to do their jobs have access to the network via mobile devices, Wright says. All devices that have access to corporate email must have a locking mechanism so that repeated failed attempts to guess a PIN will wipe the device.
17% Neither:
31%
Neither: 23%
Disagree: 60%
Looking ahead to 2013, IT executives will continue efforts to use available tools and services to reduce the risk from mobile devices. "I anticipate BYOD being an area of focus in 2013, and therefore I may seek help with anything from writing the policy to evaluating and implementing solutions for mobile device firewalls, [antivirus tools] and management software," says Libiszewski. HomeTown Bank plans to use a softwareas-a-service mobile device management tool to ensure that devices are being used properly. The software will let the bank define PIN requirements, remove an application from a device remotely or perform a full data wipe if needed, says Wright. The bank will also conduct annual refresher training on the minimum requirements for device security and regulatory compliance for employees with devices that access corporate email. In addition, it will provide ongoing education on social engineering techniques, malware avoidance and acceptable use. Organizations in the coming year will be looking for more management tools to help ensure document security and network security without infringing on employees' privacy or asking them to change their normal patterns of using devices, says Vishal Jain, a mobile services analyst at 451 Research. "We think mobile security, app management, intelligence and threat detection will be in demand," Jain says. The risks associated with mobility will only increase as more people bring their own devices to work and threats become more sophisticated. "The biggest threat that enterprises face is the loss or theft of devices containing enterprise data," he says. It's vital to have a formal mobile risk strategy and include that as a part of information security guidelines, says Jain, noting that "employees are already bringing devices to [the] workplace," essentially creating "unmanaged BYOD programs."
Vioiino is a freelance writer in Massapequa Park, N.Y. You can reach him at bviolino@optonline.net.
32
COMPUTERWORLO
SEPTEMBER 2 4 , 2012
Copyright of Computerworld is the property of Computerworld and its content may not be copied or emailed to multiple sites or posted to a listserv without the copyright holder's express written permission. However, users may print, download, or email articles for individual use.