11
Mobile Computing Security Baseline Working Group (MCSBWG) Mobile Technology Tiger Team (MTTT)

Mobile and Devices: Mobile Computing Security Baseline ... · Mobile Computing Security Baseline Working Group (MCSBWG) ... • Mobile Computing Decision Framework ... Mobile Computing

  • Upload
    vodung

  • View
    216

  • Download
    1

Embed Size (px)

Citation preview

Page 1: Mobile and Devices: Mobile Computing Security Baseline ... · Mobile Computing Security Baseline Working Group (MCSBWG) ... • Mobile Computing Decision Framework ... Mobile Computing

Mobile Computing Security Baseline Working Group (MCSBWG) Mobile Technology Tiger Team (MTTT)

Page 2: Mobile and Devices: Mobile Computing Security Baseline ... · Mobile Computing Security Baseline Working Group (MCSBWG) ... • Mobile Computing Decision Framework ... Mobile Computing

• Mobile Use Cases and Technological Centers of Gravity

• Target Architecture • Mobile Computing Decision Framework ▫ Mission Requirements ▫ Decision Balance ▫ Tailoring Risk ▫ Results

2

Page 3: Mobile and Devices: Mobile Computing Security Baseline ... · Mobile Computing Security Baseline Working Group (MCSBWG) ... • Mobile Computing Decision Framework ... Mobile Computing

Use Cases

Mobile Use Cases and Technological Centers of Gravity

3

MDM

MAS

ICAM

Data

Page 4: Mobile and Devices: Mobile Computing Security Baseline ... · Mobile Computing Security Baseline Working Group (MCSBWG) ... • Mobile Computing Decision Framework ... Mobile Computing

Target Architecture

Page 5: Mobile and Devices: Mobile Computing Security Baseline ... · Mobile Computing Security Baseline Working Group (MCSBWG) ... • Mobile Computing Decision Framework ... Mobile Computing

Mobile Computing Decision Framework

5

Page 6: Mobile and Devices: Mobile Computing Security Baseline ... · Mobile Computing Security Baseline Working Group (MCSBWG) ... • Mobile Computing Decision Framework ... Mobile Computing

Mission Requirements ▫ Manage Mobile

Users

Data

Location

6

Page 7: Mobile and Devices: Mobile Computing Security Baseline ... · Mobile Computing Security Baseline Working Group (MCSBWG) ... • Mobile Computing Decision Framework ... Mobile Computing

Decision Balance

• Security • Economics • Capabilities

7

Security

Capabilities Economics

Page 8: Mobile and Devices: Mobile Computing Security Baseline ... · Mobile Computing Security Baseline Working Group (MCSBWG) ... • Mobile Computing Decision Framework ... Mobile Computing

Tailoring Risk

• Policy

• Legal

• Technology

• Operations

• Privacy

• Security

• Financial

8

Financial

Policy

Legal

Technology Operations

Privacy

Security

1 2 3 4 5 1 2 3 4 5 1 2 3 4 5 1 2 3 4 5 1 2 3 4 5 1 2 3 4 5 1 2 3 4 5

For Example Only

Page 9: Mobile and Devices: Mobile Computing Security Baseline ... · Mobile Computing Security Baseline Working Group (MCSBWG) ... • Mobile Computing Decision Framework ... Mobile Computing

Results Buckets

• Policy • Legal • Technology • Operations • Privacy • Security • Financial

9

Management

Technical

Operational

Page 10: Mobile and Devices: Mobile Computing Security Baseline ... · Mobile Computing Security Baseline Working Group (MCSBWG) ... • Mobile Computing Decision Framework ... Mobile Computing

Results - Policy • Policy • Legal • Technology • Operations • Privacy • Security • Financial

• AC-1 T • AC-2 T • AC-2(1) T • AC-2(3) T • AC-2(4) T • AC-2(12)r4 T • AC-7(1) T • AC-7(2) T • …

10

Page 11: Mobile and Devices: Mobile Computing Security Baseline ... · Mobile Computing Security Baseline Working Group (MCSBWG) ... • Mobile Computing Decision Framework ... Mobile Computing

Results – MDM – Policy Gravity Requirement Description Threshold

or Objective Type Control M/O/T

MDM PLCY-AC-2 A formal documented policy that describes all access controls/ requirement

T M

PLCY-AC-2(4)

Account mgmt activity is audited - personnel responsible for acct mgmt are notified of activity/changes

T O

… … … …

11