With more and more people using smartphones such as the iPhone or the Droid, it’s inevitable that they want to use them for business applications such as e-mail. The smart network administrator will get out in front of the demand by putting in place policies and best practices designed to protect the network while also enabling the workers. Fiberlink Communications provides its best practices for managing smartphones.
Now that the iPhone 4 is here, even more people are sure to jump on the smartphone bandwagon. As surely as the device owners love to visit the app stores to download the latest applications, they’ll also want to use their powerful little phones to access their corporate networks, at least for company e-mail.
A brief history of smartphones
That poses a challenge for the network administrator who wants to enable these mobile workers but also needs to protect the network. I turned to the experts at Fiberlink Communications, a company that provides mobility-as-a-service, who suggest three levels of best practices for managing those iPhones, Droids, BlackBerries and other smartphones that are so ubiquitous today.
At the base level, start with a strong foundation — the general requirements all businesses should put in place.
1. Have a policy that’s realistic for 2010. This means you must support multiple device platforms and allow personal devices. Chances are your company already has a BlackBerry corporate standard. What’s more, there probably are a few iPhones and Windows Mobile devices that synch to your Exchange server by enabling Exchange Activesync. In fact, Exchange is easy to integrate with on a mobile device via the Activesync functionality. Just Google “setting up iPhone on Exchange” and see how your employees are doing it. By enabling the use of personal devices, your company can benefit from higher productivity from your workers.
2. Take stock by putting in place a multi-platform reporting and inventory tool, immediately. A lot of the decisions and risk regarding mobile devices are hard to make and quantify because businesses don’t have good data on their mobile devices. For instance, it’s not uncommon to uncover terminated employees with corporate mobile devices that are still functioning. This can be solved with a lightweight reporting and inventory tool. Make sure your solution works for help desk troubleshooting; is accessible outside of IT (for instance, HR should have read only access during exit interviews to avoid the previously mentioned issue); and has strong application inventory and search capabilities, as those will become increasingly more important.
3. Enforce the basic security precautions – password, encryption and remote wipe. You should require a strong password; have the device auto-lock after five to 15 minutes of non-use; and auto-wipe after 10 failed login attempts. Also, enforce that local encryption is enabled and be able to remotely wipe the device if it’s reported lost.
Leverage your existing infrastructure to do this. If you have a BlackBerry Enterprise Server, then you are covered on that platform. If you have Exchange, you can enforce your PIN policy and remote wipe your iPhones/iPads and Windows Mobile devices today, and Android just added this type of Exchange-based security control in version 2.2.
The biggest issue with this approach is that reporting is limited and not scalable. But this first step can dramatically improve your current posture on the popular iPhone and Android devices, while you are planning a more scalable and robust management and security solution.
4. Make Bluetooth hidden or non-discoverable. This is tricky in practice, as users will need to put the device into discover mode to pair with their car or new headset. But then have a policy requiring that users turn it back to non-discoverable when done with that one-time action in order to be qualified for corporate use.
5. Start planning for a single console, multi-platform Mobile Device Management (MDM) solution. Your BlackBerry Enterprise Server is likely well entrenched operationally and economically. But since it is not multi-platform, you will need to implement a multi-platform solution. Here are four emerging best practices to consider that map to our economically frugal and cloud-based times:
a) The lines between laptops, tablets and smartphones will continue to blur in both user functionality and IT operations. In order to prepare for this, you should strongly consider a MDM platform that also can manage PC/Mac form factor and OS devices. This will cut down on infrastructure costs, improve operational efficiency, and create a single user view into devices and data for operations and security.
b) Be sure that your reporting/inventory tool consolidates both your existing BlackBerry solution and your multi-platform MDM platform. You will rely on your data and reporting daily and should avoid any manual processes to access your business intelligence on mobile devices.
c) Consider a Web or cloud-based MDM service to manage remote, mobile devices.
d) Go the agent route with caution. If you can meet your needs with server side management controls, that will prove to be the better solution for the long haul, given the proliferation of hardware/OS/carrier combinations that an agent-based solution has to keep up with across the mobile landscape.
6. Get into the habit of reporting on and discussing mobile device inventory and policy status in your IT operations reviews, including personal devices. It’s a good way to gain exposure of the benefits for your organization and the future resource needs. Your inventory and reporting tool should make this simple.
These above practices should meet most organizations’ needs. Tune in next week to read about the next two levels of security: “advanced” and “fortress.” Meanwhile, take advantage of Fiberlink’s series of Webinars about managing mobile devices here.




