UC
A number of highly publicized security vulnerabilities are creating concern over enterprise adoption of the Apple iPad. A security group that had identified a long-standing buffer overflow vulnerability in the Safari browser claimed this week that the browser flaw was fixed in MacOS but left unpatched on the iPad. This followed their disclosure of 114,067 email addresses harvested from an insecure web script on AT&T’s web site used for iPad activation. From the first day of the iPad launch, enterprise network managers reported the presence of thousands of the devices on corporate networks. While 46% of companies say that consumer technologies are impacting IT plans, the trend towards consumerization of IT leads to this discrepancy between the perceived value and plethora of corporate applications of the iPad and the lack of standards, policies or controls for them in enterprise security. Despite these challenges, iPads are coming, ready or not. IT managers must define policies, apply controls and try to wrap corporate security around iPads and iPhones. Be prepared to define acceptable-use rules for the cases where the device security is not sufficient. Meanwhile, evaluate third-party enterprise-class security solutions for these types of devices, even if they are not primarily marketed to enterprises. We expect the market for third party monitoring and managing services to rapidly expand.




