26
Getting a Grip on Getting a Grip on Mobile Devices Mobile Devices

Risk Factory: Getting a Grip on Mobile Devices

Embed Size (px)

DESCRIPTION

%Ways to Get

Citation preview

Page 1: Risk Factory: Getting a Grip on Mobile Devices

Getting a Grip on Getting a Grip on Mobile DevicesMobile Devices

Page 2: Risk Factory: Getting a Grip on Mobile Devices

Last year thousands of Last year thousands of travellers left personal travellers left personal items in London taxi cabs items in London taxi cabs

Page 3: Risk Factory: Getting a Grip on Mobile Devices

27 toilet seats27 toilet seats

Page 4: Risk Factory: Getting a Grip on Mobile Devices

4 sets of false teeth 4 sets of false teeth

Page 5: Risk Factory: Getting a Grip on Mobile Devices

3 dogs 3 dogs

Page 6: Risk Factory: Getting a Grip on Mobile Devices

2 babies 2 babies

Page 7: Risk Factory: Getting a Grip on Mobile Devices

1 cat 1 cat

Page 8: Risk Factory: Getting a Grip on Mobile Devices

1 pheasant 1 pheasant

Page 9: Risk Factory: Getting a Grip on Mobile Devices

Funeral ashes Funeral ashes

Page 10: Risk Factory: Getting a Grip on Mobile Devices

A dead bodyA dead body

Page 11: Risk Factory: Getting a Grip on Mobile Devices

Over 75,000 mobile Over 75,000 mobile computing devicescomputing devices

Page 12: Risk Factory: Getting a Grip on Mobile Devices

These devices can hold These devices can hold

10k 10k photosphotos

200k 200k docsdocs

100k 100k emailsemails

Page 13: Risk Factory: Getting a Grip on Mobile Devices

How do you Get a How do you Get a Grip on that?Grip on that?

Page 14: Risk Factory: Getting a Grip on Mobile Devices

Top 10 Risks Top 10 Risks 1. Loss2. Theft3. Malware 4. Stealth installs5. Data interception 6. Direct attack 7. Call hi-jacking8. VPN hi-jacking9. Session hi-jacking10.Device hi-jacking

Page 15: Risk Factory: Getting a Grip on Mobile Devices

Step 1Step 1

Quantify the Quantify the ProblemProblem• Stop.• First measure the problem• Conduct a survey• How many devices? Running what applications? • Processing, storing, transmitting: what data?• Draft Asset Register• Draft Risk Register

Page 16: Risk Factory: Getting a Grip on Mobile Devices

Step 2Step 2

Draft policies Draft policies

• Device ownership• Device liability• Acceptable devices• Acceptable use• Acceptable applications• Minimum device security requirements• Where to report lost/stolen devices• Security Awareness Program

Page 17: Risk Factory: Getting a Grip on Mobile Devices

Consider…Consider…

• Mandating the use of PINs to access devices• Mandating use of complex passwords to access

applications• Set max number of password failures • Set max days of non-use lock out• Specify password change interval• Prevent password reuse via password history• Set screen-lock

Page 18: Risk Factory: Getting a Grip on Mobile Devices

Step 3Step 3

ConfigurationConfiguration

• Firewall• Anti-virus (Malware, Trojans, Spyware)• O/S Updates• Hardening• Back end support servers• VPN dual authentication

Page 19: Risk Factory: Getting a Grip on Mobile Devices

• Adding or removing root certs• Configuring WiFi including trusted SSIDs, passwords, etc.• Configuring VPN settings and usage• Blocking installation of additional apps from the

AppStore• Blocking GeoLocation• Blocking use of the iPhone’s camera• Blocking screen captures• Blocking use of the iTunes Music Store• Blocking use of YouTube• Blocking explicit content

Consider…Consider…

Page 20: Risk Factory: Getting a Grip on Mobile Devices

20

Page 21: Risk Factory: Getting a Grip on Mobile Devices

Step 4Step 4

EncryptionEncryption

• Data• Disk• Document, File & Folder• Laptop• Port & Device Controls• Removable Media &

Device• Email

Page 22: Risk Factory: Getting a Grip on Mobile Devices

Step 5Step 5

Incident responseIncident response

• Included in BC/DR Plan• Back ups• Alternatives: – Find it– Track it– Kill it

Page 23: Risk Factory: Getting a Grip on Mobile Devices

How to Get a GripHow to Get a Grip

Quantify the problempoliciesConfiguration Encryption Incident Response

Page 24: Risk Factory: Getting a Grip on Mobile Devices

SourceSource

Page 25: Risk Factory: Getting a Grip on Mobile Devices

the problem in handthe problem in hand

Page 26: Risk Factory: Getting a Grip on Mobile Devices

26 Dover Street 26 Dover Street LondonLondon

United KingdomUnited KingdomW1S 4LYW1S 4LY

+44 (0)20 3586 1025+44 (0)20 3586 1025www.riskfactory.comwww.riskfactory.com

A different perspectiveA different perspective