On CNET: 7 essential free apps for PC
BNET Business Network:
BNET
TechRepublic
ZDNet

By Joris Evers
Posted on ZDNet News: Nov 16, 2005 4:30:00 AM

WASHINGTON--The many gadgets carried around by workers today pose a real security risk to organizations and require action, session attendees at a security conference agreed Tuesday.

Smart phones, handheld computers, thumb drives, digital cameras, iPods and other MP3 players can all connect to computers. That's fine when used at home, but when connected to a work PC, the devices can pose a serious risk, said Norm Laudermilch, chief security officer at Trust Digital, a McLean, Va., mobile security vendor.

Connecting the gadgets to work PCs could lead to a number of unwanted scenarios, Laudermilch said. For example, malicious code that crept onto the device at home could enter the corporate network unseen by the firewall or intrusion detection software, he said.

Also, a disgruntled employee could copy confidential information to the device and walk out with it. Classified information on a mobile device could be a business risk even when used by loyal workers, when their gadget is lost or stolen, for example.

Laudermilch spoke at the annual Computer Security Institute conference here. When he asked the room filled with security professionals if they thought mobile devices were an issue, the vast majority raised their hands.

The advent of mobile devices has changed the way security professionals should think about securing their networks, Laudermilch said. That's because networks change all the time, with different types of devices being added and removed, he said.

"Things change very quickly when devices are so small and just walk onto your network," Laudermilch said. "Your network perimeter is where your data is. I don't care if it is somebody walking in Paris, or somebody sitting at home. The security perimeter has drastically changed."

He also highlighted challenges in securing the portable gear. For one, they all run different operating systems. "We have all been training about the right things and wrong things to do with the Windows operating system," Laudermilch said. For smart phones alone there are at least four common systems: Palm, Windows, BlackBerry and Symbian.

Also complicating security is that new devices come out constantly, with different features. When it comes to phones, operators install their own software image on the hardware, Laudermilch said.

An upcoming class of software can help organizations manage devices on their network, or block the gadgets from connecting altogether. Many of the applications also encrypt data on devices, for security in case of loss or theft. Trust Digital sells such products, as do a host of other companies.

Gartner says mobile data security is a tiny market, but such products are needed to protect user privacy and fulfill audits, according to the analysts. Small incumbent vendors dominate the space, Gartner said in a July report.

"Mobile security today is a buzzword. Tomorrow, six months or a year from now, it is going to be just security. Everything is going mobile," Laudermilch said

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 20 Talkback(s)
In theory - great, in these times - iffy
The respect and dignity thing should go both ways, and employers who treat employee's poorly and disrepectfully shouldn't wonder where bad situations spawn.

Certain jobs more than others need t... (Read the rest)
Posted by: Boot_Agnostic Posted on: 11/17/05 You are currently: a Guest | | Terms of Use
Device usage  Arnout Groen | 11/16/05
VPNs aren't secure  voska | 11/16/05
Why am I not surprized  BXLE | 11/16/05
Most of the problems here are related to Windows. This is easy to fix.  DonnieBoy | 11/16/05
And Linux fixes this how?  wolf_z | 11/16/05
More Anti-Windows blather  srobtjones@... | 11/16/05
Why is this suddenly a problem today?  voska | 11/16/05
Security is opposite of convenience.  osreinstall | 11/16/05
I somewhat concur  srobtjones@... | 11/16/05
About employee rentention  osreinstall | 11/16/05
Here is an idea...I know it's radical and all  Laff | 11/16/05
Sounds like a great idea.  osreinstall | 11/16/05
Continuation of Radical . . .  millenia01 | 11/16/05
not the point, I think  srobtjones@... | 11/16/05
Doesn't work  voska | 11/16/05
In theory - great, in these times - iffy  Boot_Agnostic | 11/17/05
Simple,  bjbrock | 11/16/05
Tightrope walking indeed  srobtjones@... | 11/16/05
Well, you'll need to lock down the cdrom as well  Boot_Agnostic | 11/16/05
Return to the proprietary mainframe  terry flores | 11/16/05

What do you think?

advertisement
advertisement
Click Here

White Papers, Webcasts, and Downloads

Meet Doc