- Steve Jobs is a man of a few words
- Internet routing blasts into space
- 15 free downloads to pep up your old PC
- IBM smartphone software translates 11 languages
- New attack fells Internet Explorer
For years analysts have encouraged the consumerization of IT to enhance collaboration and productivity. It began with adoption of consumer instant messaging applications and continued with Web 2.0 technologies such as Wikis and social networking. Now, as employees start bringing their smartphones to work and request IT to provide access to email and other corporate applications, we are seeing the consumerization of not just an application but an entire computing platform.
At first glance this looks like a great idea. IT increases employee satisfaction, reduces OpEx costs by having employees foot part of the wireless bill, and cuts CapEx costs by ducking the cost of the pricey phones. What’s more, employees with smartphones devote more personal time to work so there is a productivity gain.
Early data from the Aberdeen Group shows that 20% of companies surveyed allow their employees to use personal devices for work.
But securing employee-owned smartphones is not the same as securing corporate-owned devices. In the corporate model, if an
employee leaves the company, standard procedure is to retrieve the phone and “brick” it, wiping it clean of all data and resetting
it to factory defaults. In the new model, when an employee leaves the company the phone goes too, packed as it is with personal
pictures, videos, contacts, applications, music and confidential corporate information.
Is it fair to wipe all personal information from a phone just because an employee tried to be more productive for the company?
At the same time, is it damaging to the company’s business to compromise security levels just because that employee happens
to own the phone?
Enterprise data boundary
The way to address this issue is to start by adopting a framework that provides visibility into corporate data on an employee’s smartphone and allows administrators to set boundaries around this data. This doesn’t have to be something as fancy as tagging or fingerprinting mobile files. It can start with simply drawing a line between media files on one side and xls, doc, ppt, and pdf documents on the other.
The key is that however this enterprise data boundary is drawn, if an employee leaves the company, he or she should be able to take the phone with personal data intact, while IT should be able to ensure that any corporate information has been safely removed. The process should be simple and transparent to all.
In addition to segmenting personal information from corporate, IT must have an honest dialogue with employees about the trade-offs that exist when attaching a personal smartphone to the enterprise. For instance, regulatory compliance policies may mandate that corporate communications be archived for e-discovery purposes. These communications can include SMS messages, therefore, the employee must weigh the privacy concerns of having SMS archived in the same manner as corporate e-mail.
IT will likely find that different policies will apply between corporate-owned and employee-owned phones, so it’s crucial for the policy enforcement framework to delineate between phones based on ownership.
Comments (9)
Risk without solutionsBy Anonymous on October 16, 2009, 3:33 pmGreat to point out the risk, thanks, but how about specifics as to where to find the solutions that provide tools for the IT Admin to effectively wipe one file type...
Reply | Read entire comment
Their phone, your headache By Anonymous on October 16, 2009, 4:50 pmIn my company I am building applications that use the phones web interface to house corporate data, thus reducing the need for corporate data to sit on the phone....
Reply | Read entire comment
Their phone, your headache commentsBy Ojas Rege on October 16, 2009, 10:14 pmKeeping data server side and presenting it through the web is definitely a way to reduce the risk and complexity of client-side data. The challenge has been with...
Reply | Read entire comment
We have a solution to the employee/company owned data/accountabiBy Anonymous on October 17, 2009, 12:12 pmWe have a solution to the employee/company owned data/accountability issue. What if you could see real time all information that is passed to and from the phone/pda/BB?...
Reply | Read entire comment
"bricking" does not mean "reset to factory default"By Anonymous on October 19, 2009, 3:35 amminor point, though
Reply | Read entire comment
We don't allow personal devices of any kind on our network...By Anonymous on October 19, 2009, 2:07 pmWe don't allow personal devices of any kind on our network. If we get personal data on the business equipment, it's up to us to get it off.
Reply | Read entire comment
View all comments