Securing information in a mobile world

Maintaining control of data is now a greater challange than ever, but there are solutions, as Symantec Pacific vice-president Craig Scroggie explains.

Whether it's an employee making a tree change or a sea change, an executive who spends the majority of their time on the road, or simply a staff member who wants to stay connected outside of work hours, remote and mobile workers are now firmly entrenched in Australian businesses.

Within Australia, we have seen an explosion in the popularity of endpoint devices - such as mobile phones, PDAs and laptop computers - to meet the demand of this changing workforce. We have also witnessed a rising trend of employees choosing to use personal devices on the corporate network rather than company-issued devices, and an increasing adoption of DVDs and USB storage devices in the workplace.

Social networking is also being embraced by organisations both internally and externally, and in many cases it is now the norm to allow employees to access popular social networks and use wikis to improve information-sharing between teams and enhance productivity. However, with the rise of web-based attacks, protecting these interactions has become critical. According to Symantec's latest Internet Security Threat Report, web-based attacks are now the primary attack method and 63 per cent of vulnerabilities reported in 2008 affected web applications.  

The bottom line is that we now live in a world where information can be accessed virtually anywhere, anytime, and from any device. And while businesses are embracing these changes, many are struggling to adequately protect their information, which is now is as mobile as their workforce. The result is that businesses are changing the way they secure their information. Rather than security revolving solely around a company's infrastructure or devices, it now should revolve around an organisation's most important asset: their information.

Managing Risk in a Mobile World
So how can organisations reap the productivity and business advantages that come hand-in-hand with these recent trends without exposing themselves to an additional set of IT security risks? The answer lies in protecting the information as well as the device it resides on through the implementation of security technologies, development of policies and processes, and education for all employees and visitors to the network.

One of the most important ways a company can protect their information is by managing access to confidential information. This in turn minimises the number of mobile devices this information can be accessed from and consequently reduces the chance of a breach. In addition, by installing the right data loss prevention technologies, the processes supporting these policies can be automated and provide a range of options to quickly respond to policy violations.

For example, a business might decide to establish a policy stating employees cannot put customer credit card data on a USB key. To support this policy, it installs a data loss prevention solution that recognises this information and when it is copied. One day this technology registers that an employee has downloaded a spreadsheet containing credit card numbers onto a USB device and issues an alert that triggers a series of processes. The business is then in a position to warn the employee, lock down the computer's USB drive, isolate the computer from the network, or take other appropriate actions.

These policies and technologies can also provide a business with options if the information, regardless of the medium, is lost or stolen. This includes barring network access from the device, disabling any active passwords, and quickly identifying any sensitive information that may reside on it.

You must be a registered member to access this content.
Please Sign in below or Register now.
NOTE: This Feature is more than 7 days old.
Please login to view the rest of this article

Login above or Register now and get unlimited access.

Already subscribed but have forgotten your login? Recover your password your here.


Why sign up?
  • Unlimited access to SC Magazine content as well as access to to our global resources from SC Magazine US and UK editions.
  • Full use of over 11,000 articles database covering breaking news, video interviews, case studies, research, product reviews and exclusive features with fast and intuitive filtering of results.
  • Personalised "Recommended for you" filters to ensure you have the most relevant content at your finger tips.
  • Daily security bulletin direct to your inbox covering the latest security news from Australia/NZ and around the world.

Register now, its free! We'll never sell your details to third parties and it helps SC Magazine to keep serving you quality stories.
Sign up to receive SC Magazine email newsletters
   FOLLOW US...
Most Read