Lock down your mobile handheld devices for ultimate security

Opinion
Mar 3, 20115 mins

No doubt you’ve been dealing with (overwhelmed with?) users wanting to use their smart phones and tablets to access company email and perhaps other corporate applications. It may be sufficient to let them use ActiveSync to get their email on their iPhones, Droids and other snappy new devices. But what if you need a much more secure mobile environment? What if you need to ensure compliance with PCI, or HIPAA, or FISMA? That requires a much more comprehensive approach to mobile security.

Traditional security approaches don’t work well for smart phones and tablets. Conventional firewalls, antivirus tools and other scanners are bandwidth and battery hogs. Downloading and updating these utilities take too many resources that cause device performance to sag. Quite simply, it’s a failed approach for the mobile platform.

Many mobile security vendors base their device management solutions on Mobile Device Management (MDM) software, which is native to Apple’s i-devices and, to a lesser extent, some Android-based devices. There’s just one hitch with MDM: the user can actually turn the security off.

A company called Mobile Active Defense (M.A.D.) has taken a different approach to mobile security. M.A.D. has taken all the traditional capabilities for security and compliance from the fixed (stationary) enterprise, added mobility and geo-location capabilities, and came up with a solution that effectively offers the same level of security and compliance for the mobile enterprise as you have with your fixed enterprise. The solution does not require a footprint on the device, and all policies are applied on a dynamic basis based on a device’s changing physical location. What’s more, the user doesn’t have to do anything and his experience doesn’t change (unless dictated by policy).

The key to this approach is a certificate authority (CA) that does the first level provisioning of the device. (The CA can either be M.A.D.’s or your own.) M.A.D. locks down the device by enforcing an always-on VPN. Once the VPN is enforced, all data traffic goes through M.A.D.’s servers, which are either hosted by M.A.D. (typically for small businesses) or by corporations in their own data centers. Every bit of the data traffic going in and out of the device is encrypted.

Then it’s a matter of enforcement policy, and there are two ways to set up the policies. In the first way, you can take your existing corporate policy sets and move them over into M.A.D.’s configurations and console. You can bring in your LDAP user population, which brings in your existing user groups and how you treat enterprise users. If you take this approach, you are enforcing firewall rules that basically make the devices invisible to the Internet.

A second approach is to develop your mobile policies completely from scratch after you bring in your LDAP. Each smart phone then has its own virtualized firewall instance on the server.

An administrator manages the devices through a console. You can do things like configure filtering to prohibit the device from going to categories of websites such as adult, gambling or social media; blacklist applications you don’t want people to use or install; filter mail for viruses and spam; and much more. The administrative tools look very similar to a regular firewall admin product. This helps reduce the learning curve for the administrator.

M.A.D. also has remediation services so you can detect what users are doing that could violate policy. Detection takes place within seconds and an administrator can take any number of prescribed actions based on policy; for example, sending a warning to the user or wiping the disk of sensitive data.

A critical aspect of the M.A.D. solution is that it offers time based security and geo-location based rules. For example, an activity that is perfectly acceptable on a weekday between 8 A.M. and 5 P.M. might be forbidden on weekends or after hours. Or, a device can be used or an activity can be permitted within a specific location range. For instance, it’s OK to access a corporate application while the user is within the U.S., but this action is prohibited if the device is used in China.

As corporations enable more and more true enterprise applications via mobile smart phones and tablets, the need for tight security on these devices will grow. Mobile Active Defense has a non-intrusive solution that mirrors in the mobile world what you’ve already built for your fixed environment.

Linda Musthaler is a Principal Analyst with Essential Solutions Corporation.  You can write to her at mailto:LMusthaler@essential-iws.com.

About Essential Solutions Corp:  Essential Solutions researches the practical value of information technology, and how it can make individual workers and entire organizations more productive.  Essential Solutions offers consulting services to computer industry and corporate clients to help define and fulfill the potential of IT.