joanie_wexler
Writer

Boeing laptop theft spotlights fragile state of mobile security

Opinion
Dec 18, 20062 mins

* The time has come for mobile security policies and processes

It’s time for the CXOs, the CIO and the IT group in your organization to call a cross-departmental powwow and cement mobile security processes. Not only must mobile-device policies get built; processes must be put in place to make sure that they are, indeed, executed.

I reported here last month that 40% of the respondents to a 700-organization survey conducted by the Business Performance Management Forum admitted not having necessary policies in place to protect sensitive data residing in mobile devices. A similar percentage said it would take a security breach to prompt their organizations to get those security measures in place.

Well, even two breaches might not be motivation enough for some companies. For the third time in about a year, a laptop storing unencrypted personnel information has been stolen from the Boeing Co., putting 382,000 Boeing retirees and active workers at risk for identity theft and credit card fraud. The files on the computer, stolen the first week in December, contained employee and retiree names, social security numbers and, in most cases, home addresses, phone numbers and birth dates, the Chicago Sun-Times reported last week.

A 2006 report by the SANS Institute says the greatest IT concern for businesses in 2007 should be laptop security. The mix of sensitive data being taken outside organizations, lack of encryption, and human error mean that lost or stolen devices are posing a bigger threat than ever before, according to the report.

We’ve got to get smarter about all this.

Security policies aren’t worth much if there is no way to enforce user compliance. To do so requires installing policies on each device before it is used, then conducting periodic audits of each device to ensure that they are in compliance. These policies might include a corporate standard for password protection, local data encryption, and the ability to erase data from the device if multiple incorrect password attempts are made or if a device is reported as lost or stolen.

You could leave it up to the end user to report whether or not their laptops store confidential data. As with many aspects of security, though, this might seem troublesome to users, who are likely to circumvent the process. Better to have an automated checking, reporting and remediation process in place.

joanie_wexler
Writer

Joanie Wexler is an independent writer and editor who has spent 20+ years writing about computer networking technologies, their business potential, and implementation considerations. She serves clients at technology companies and industry publications writing educational materials on all aspects of IT.

More from this author