Showing posts with label personal devices. Show all posts
Showing posts with label personal devices. Show all posts

Monday, January 21, 2013

HELLO, My Name is Cloud_009...

 ...scrolls across the small 16:9 LCD protruding from my chest cavity. 

In case you missed it, I'm from the future, where we all have become our own personal cloud.  Some clouds you can actually see, like auras, but look somewhat like the classic Peanuts character Pigpen.  We've all become walking antennas, routers, hotspots and hubs for all the other personal clouds.  If auto-discovery is enabled, once you are in range of a 'friend' that you 'like,' a few beeps go off and they appear as an icon right in our own retina.  You remember those smart phones that allowed users to tap the phones to send a picture or file?  Now, all we have to do is crank up some digital audio and do a move called 'The Bump.'  It's based on some ancient 1970's fad dance where participants would lightly 'bump' hips to the beat of the music.  Today we use it to exchange data.  A bump or two and you've shared your music library.  A hip-check, your movie collection.  Passing gas is kinda like your old computer's recycle bin that you need to empty every so often.

All this works in conjunction with the IPv6 chip inserted into the freshly cut umbilical cord of every newborn, so it heals right into the system.  As you grow, the bellybutton also becomes a power source - you can interchange belly-ring connections and power almost any device with the solar plexus.  But we really do not carry 'mobile' devices anymore since their functionality is now mostly built in to our carcasses.  Our ear and earlobe have evolved to have the capability of answering calls or listening to audio just by pushing in the outer ear plug or as you used to call it, the tragus.  The earlobe itself is a highly sensitive bio-metric scanner that'll check your thumbprint and if authenticated, will unlock your car, home or any other item that you program. 

We each have a cloud identifier to distinguish our identity.  I'm Cloud_009.  I used to be Cloud_337528 but since I'm usually happy, have a strong security posture and graduated from ISO University, I was recently upgraded.  You're probably wondering if I know Cloud_007.  We've met a couple times but I try to stay away from the espionage cloud since you really don't know what you may catch in there.  Lots of infecting, crashing and drive-by Bumps. 

I'm also able to segment parts of my cloud for work and play.  Some clouds do top half/bottom half but I like to go right down the middle.  When enabled, my right side handles my work/corporate data and the left does my personal stuff.  Because I'm flexible, the percentages can adjust on the spot when the demand goes up.  From 9-5, I might use up to 80% of my cloud-body for work related computations with the other 20% reserved for bathroom breaks, eating, breathing, recharging and any other personal activities.  The data stays separate, secure and encrypted. 

Well, I got a hologram coming in that I need to watch but it was nice talking with you.  We don't do much of that anymore since most messages are sent telepathically these days.

ps

Related:

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Thursday, October 18, 2012

BYOD Policies – More than an IT Issue Part 3: Economics

#BYOD or Bring Your Own Device has moved from trend to an permanent fixture in today's corporate IT infrastructure. It is not strictly an IT issue however. Many groups within an organization need to be involved as they grapple with the risk of mixing personal devices with sensitive information.  In my opinion, BYOD follows the classic Freedom vs. Control dilemma. The freedom for user to choose and use their desired device of choice verses an organization's responsibility to protect and control access to sensitive resources. While not having all the answers, this mini-series tries to ask many the questions that any organization needs to answer before embarking on a BYOD journey.

Enterprises should plan for rather than inherit BYOD. BYOD policies must span the entire organization but serve two purposes - IT and the employees. The policy must serve IT to secure the corporate data and minimize the cost of implementation and enforcement. At the same time, the policy must serve the employees to preserve the native user experience, keep pace with innovation and respect the user's privacy.  A sustainable policy should include a clear BOYD plan to employees including standards on the acceptable types and mobile operating systems along with a support policy showing the process of how the device is managed and operated.

Some key policy issue areas include: Liability, Device Choice, Economics, User Experience & Privacy and a trust Model.  Today we look at Economics.

Many organizations look at BYOD as an opportunity to reduce some costs. Clearly, not having an equipment cost - $200-$600 per-device - can add up depending on the company's size. It might also make financial sense for a smaller company with few employees. Since the phone is owned by the employee, then they are probably responsible for the bill every month. Depending on their personal contract/plan, excessive charges could arise due to the extra minutes used for work related calls. Often, monthly charges are fairly consistent with established plans, and while there are times when the bill is higher due to an incidental charge to some other overage, many people fail to review their phone bill when it arrives. BYOD could force employees into a higher monthly service plan but it also gives users visibility into their usage, if for instance, the corporate BYOD policy allows for reimbursement. This can drive personal responsibility for how they use their minutes.

While BYOD could reduce the overall expenditure for IT issued devices and many organizations report employees are happier and more productive when they are using the device of their desire (an enablement tool), there might be other areas that costs could increase.  While the employee does spend their own money on the device, there are certainly enterprise costs to managing and securing that device.  There could also be a snag however when it comes to licensing.  Does BYOD also require Bring Your Own License?  In many instances, this is an area that IT needs to keep an eye on and often the answer is yes. 

Some of the most common enterprise software licensing agreements require licensing any device used "for the benefit of the company" under the terms of the enterprise agreement.  That often means that all those BYO devices might require a license to access common corporate applications.  This also means that even if the user already has a particular license, which they purchased on their own or it came with the device, the organization might still need to license that device under their enterprise software agreement.  This could diminish any cost savings from the BYOD initiative.  There are solutions to such as using alternative products that are not restricted by licensing but, those may not have the key features required by the workforce.  IT needs to understand if their license agreements are per-user or per-device and what impact that may have on a BYOD policy.

A few questions that the Finance department should determine is: Should the company offer users a monthly stipend? How is productivity measured?  Will the management and security cost more than IT (volume) procurement?  What are the help desk expenses and policy about support calls. There certainly needs to be discussion around mobile app purchase and deployment for work use. Are there any compliance, additional audit costs or tax implications with a BYOD initiative?

As part of the BYOD Policy the Economics Checklist, while not inclusive, should:

· Investigate the effects of a BYOD reimbursement plan on your ability to negotiate with wireless carriers

· Consider putting logging and reporting in place to monitor after-hours use

· Incorporate a “help desk as a last resort” guideline into your employee BYOD social contract

· Estimate costs for any increased need for compliance monitoring

· Ask Finance about tax implications (cost or benefit) of a BYOD policy

 

ps

Related

Technorati Tags: F5, data breach report, threats, Pete Silva, security, malware, technology, smartphone, cyber-threat, social engineering, attacks, virus, vulnerability, web, internet, cybercrime, identity theft, scam, data breach

 

Connect with Peter:

Connect with F5:

o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Wednesday, October 17, 2012

BYOD Policies – More than an IT Issue Part 2: Device Choice

#BYOD or Bring Your Own Device has moved from trend to an permanent fixture in today's corporate IT infrastructure. It is not strictly an IT issue however. Many groups within an organization need to be involved as they grapple with the risk of mixing personal devices with sensitive information.  In my opinion, BYOD follows the classic Freedom vs. Control dilemma. The freedom for user to choose and use their desired device of choice verses an organization's responsibility to protect and control access to sensitive resources. While not having all the answers, this mini-series tries to ask many the questions that any organization needs to answer before embarking on a BYOD journey.

Enterprises should plan for rather than inherit BYOD. BYOD policies must span the entire organization but serve two purposes - IT and the employees. The policy must serve IT to secure the corporate data and minimize the cost of implementation and enforcement. At the same time, the policy must serve the employees to preserve the native user experience, keep pace with innovation and respect the user's privacy.  A sustainable policy should include a clear BOYD plan to employees including standards on the acceptable types and mobile operating systems along with a support policy showing the process of how the device is managed and operated.

Some key policy issue areas include: Liability, Device choice, Economics, User Experience & Privacy and a trust Model.  Today we look at Device Choice.

Device Choice

People have become very attached to their mobile devices. They customize and personalize and it's always with them, to the point of even falling asleep with the device. So ultimately, personal preference or the 'consumerization of IT' notion is one of the primary drivers for BYOD. Organizations need to understand, what devices employees prefer and what devices do employees already own. That would could dictate what types of devices might request access. Once organizations get a grasp on potential devices, they then need to understand each device's security posture.

About 10 years ago, RIM was the first technology that really brought the Smartphone into the workplace. It was designed to address the enterprise's needs and for years was the Gold Standard for Enterprise Mobility. Management control was integrated with the device; client certificate authentication was supported; Active Directory/LDAP servers were not exposed to the external internet; the provisioning was simple and secure; organizations could manage both Internet access and intranet access, and IT had end point control.

When Apple's iPhone first hit the market, it was purely a consumer device for personal use and was not business centric, like the BlackBerry. Initially, the iPhone did not have many of the features necessary to be part of the corporate environment. It was not a business capable device. It did not support applications like Exchange, which is deployed in many organizations and is critical to a user's day-to-day activities. Over time, the iPhone has become a truly business capable device with additional mechanisms to protect end users.  Android, very popular with consumers, also offers numerous business apps but is susceptible to malware.

Device selection is also critical to the end user experience. Surveys show that workers are actually more productive when they can use their personal smartphone for work. Productivity increases since we prefer to use our own device. In addition, since many people like to have their device with them all the time, many will answer emails or do work during non-work hours. A recent survey indicated that 80% of Americans work an extra 30 hours a month on their own time with BYOD. But we are much happier.

A few blogs ago, I wrote about Good Technology’s BYOD survey, found that organizations are jumping on the phenomenon since they see real ROI from encouraging BYOD.  The ability to keep employees connected (to information) day and night can ultimately lead to increased productivity and better customer service.  They also found that two of the most highly regulated industries - financial services and health care - are most likely to support BYOD.  This shows that the security issues IT folks often raise as objections are manageable and there's major value in supporting BYOD.  Another ROI discovered through the survey is that since employees are using their own devices, half of Good’s customers don't pay anything for the employees' BYOD devices – essentially, according to Good, getting employees to pay for the productivity boost at work.

As part of the BYOD Policy the Device Choice Checklist, while not inclusive, should:

· Survey employees about their preferences and current devices

· Define a baseline of acceptable security and supportability features

· Do homework: Read up on hardware, OS, and regional variances

· Develop a certification program for future devices

· Work with Human Resources on clear communication to employees about which devices are allowed–or not–and why

ps

Related

Technorati Tags: F5, data breach report, threats, Pete Silva, security, malware, technology, smartphone, cyber-threat, social engineering, attacks, virus, vulnerability, web, internet, cybercrime, identity theft, scam, data breach

Connect with Peter:

Connect with F5:

o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Wednesday, July 18, 2012

Multiscreen Multitasking

Talk about killing two birds with one stone - according to a Pew Internet & American Life Project report, more Americans on their phones while watching TV.  About half of U.S. mobile phone owners use their devices while watching TV, a new study suggests.  While most (38%) are clicking away as a commercial filler, many are enhancing their viewing experience by interacting along with the program. 

About 23% of cellphone users exchange text messages with their friends about the same show they are simultaneously watching on TV; around 20% of them visit websites mentioned on TV; 22% used their phone to check whether something they heard on television was true; 11% of cellphone owners use their devices to read what others are writing online about a particular television program; another 11% posts comments on online boards using their cellphones; and 6% used their phone to vote for a reality show contestant.  Both men and women equally are glued to their smartphone while watching TV with the 18-24 age bracket leading the way (81%), followed by the 25-34 group (72%).

The massive growth of smartphones and how we use them is infiltrating every aspect of our lives.  The most basic task of making a phone call seems miniscule compared to the many other things we do with smartphones.  Our personal devices are also becoming the primary mobile device we use for work with all the BYOD initiates being implemented.  It’s also clear that with all the other tasks and activities we use our smartphones for, providing a solid BYOD policy within an organization is important to keeping corporate resources safe.  Not sure how I turned the results of a TV survey into a BYOD challenge but there you have it.  And somehow the famous words of Homer Simpson now have much more meaning, ‘Then we figured out we could park them in front of the TV. That's how I was raised, and I turned out TV.’ 

ps

References:

Technorati Tags: F5, smartphone, integration, byod, Pete Silva, security, business, education, technology, application delivery,ipad,mobile device, context-aware,android, iPhone, web, internet, security

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Tuesday, July 10, 2012

Dreaming of Work

Say What?!?  Instead of counting sheep, I can count how many emails I need to answer in the morning?  Sure can…at least according to a recent Good Technology survey that indicates that we are working more – an average of 7 hours more per week - but it’s on our own schedule.  More than 80% of working adults in the U.S. continue to work when they have left the office adding another 30 work hours per month.  Most say it’s to stay organized, but others feel they must due to customer needs and the fact that workers find it hard to switch to off work mode when they get home.  Half of us even take the mobile device to bed and answer emails under the covers.  Amazingly, over half of those surveyed also noted that there was no argument from the significant other about the additional home-work.  The mix of personal and work lives are blurring even more.

Our mobile, always-on lifestyle is appreciated by both organizations and workers alike.  Organizations see increased productivity while workers like the freedom to get their work done wherever and whenever.  Of course, data security is always paramount and John Herrema, Good’s SVP of Corporate Strategy said, “When it comes to supporting a ‘bring your own device’ environment, it’s important to take an approach that ensures data security without compromising the employee's privacy or personal experiences. By shifting their management focus from 'devices' to 'apps' and 'data', enterprises can allow employees to get work done on the go whenever they want, and still keep personal information private, separate and safe.”

The study also revealed:

  • 68 percent of people check their work emails before 8 a.m.
  • The average American first checks their phone around 7:09 a.m.
  • 50 percent check their work email while still in bed
  • The work day is growing – 40 percent still do work email after 10 p.m.
  • 69 percent will not go to sleep without checking their work email
  • 57 percent check work emails on family outings
  • 38 percent routinely check work emails while at the dinner table

…and the Infographic:

good-infographic-usa-2

 

ps

References:

Technorati Tags: F5, smartphone, integration, byod, Pete Silva, security, business, education, technology, application delivery,ipad,mobile device, context-aware,android, iPhone, web, internet, security

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Thursday, June 28, 2012

Will BYOL Cripple BYOD?

Don’t ya love all the acronyms we have?

So by now, you’ve probably heard that BYOD means Bring Your Own Device – a topic that is getting lots of press these days.  The concept of allowing employees to use their own personal device, often mobile, for work related tasks.  This could reduce the overall expenditure for IT issued devices and many organizations feel users are happier and more productive when they are using the device of their desire.  There could be a snag however when it comes to licensing.  Does BYOD also require Bring Your Own License?  In many instances, this is an area that IT needs to keep an eye on and often the answer is yes.

Some of the most common enterprise software licensing agreements require licensing any device used "for the benefit of the company" under the terms of the enterprise agreement.  That often means that all those BYO devices will require a license to access common corporate applications.  This also means that even if the user already has a particular license, which they purchased on their own or it came with the device, the organization might still need to license that device under their enterprise software agreement.  This could diminish any cost savings from the BYOD initiative. 

There are solutions to such as using alternative products that are not restricted by licensing but, those may not have the key features required by your workforce.  Another idea is to move primarily to virtualization for provisioning apps with restrictive client access licenses.    Some software licenses require one CAL per concurrent connection, some require one CAL for each unique client regardless of concurrency and some do not require CALs at all.  IT needs to understand if their situation is per-user or per-device and what impact that may have on a BYOD policy.

ps

Related:

Technorati Tags: F5, smartphone, integration, byod, Pete Silva, security, business, education, technology, application delivery,ipad,mobile device, context-aware,android, iPhone, web, internet, security

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Thursday, April 5, 2012

BYOD–The Hottest Trend or Just the Hottest Term

It goes by many names: ‘Bring Your Own Danger’, ‘Bring Your Own Disaster’ and what most people call ‘Bring Your Own Device’ and everyone it seems is writing, talking and surveying about BYOD.  What used to be inconceivable, using your own personal mobile device/smartphone for work, is now one of the hottest trends or at least, one of the hottest topics being discussed throughout the IT industry.  The idea of using a personal smartphone at work sprouted, I think, when many executives got their first iPhone back in 2007 and wanted access to corporate resources.  As more smartphones made their way into employee’s hands, the requests for corporate access only grew.  Initially resistant to the idea due to security concerns, IT seems to be slowly adopting the concept based on the many blogs, articles and surveys that have littered the internet of late.  But, it is a true trend that will transform IT or simply a trending term getting a lot of attention?  We’ll be right back after these important messages.

Just Kidding.  Most likely the former.

While many of the cautionary articles talk about potentially grim disasters, they do acknowledge that BYOD is not going away and in fact, is gaining ground.  Greater productivity and cost savings seem to be the driving factors.  Let’s take a quick look at the smattering of articles surrounding this offshoot of IT consumerization.

The Mobile Device Threat: Shocking Mobile Security Stats:  A nice slide show featuring highlights from a recent Ponemon Institute and Websense survey.  Right out of the gate they talk about how mobile devices are a double-edge sword for enterprises.  77 % of the 4640 responses said that the use of mobile devices in the workplace is important to achieving business objectives but almost the same percentage - 76% -  believe that these tools introduce a "serious" set of risks.  While organizations understand the risks, the survey showed that only 39% have security controls in place to mitigate them.  As a result, 59% of respondents said they’ve seen a jump in malware infections over the past 12 months due, specifically, to insecure mobile devices including laptops, smartphones, and tablets while 51% said their organization has experienced a data breach due to insecure devices.  While 45% do have a corporate use policy, less than half of those actually enforce it.  In terms of recommendations based on their findings they said, be sure to understand the risk that mobile devices create in the workplace; educate employees about the importance of safeguarding their devices; create a mobile device corporate policy and leverage mobile device management solutions, security access controls, and even cloud services to keep confidential data out of the eyes of unauthorized viewers.

10 myths of BYOD in the enterprise: A nice top 10 from TechRepublic primarily pulling data from a recent Avanade survey of more than 600 IT and business leaders.  The notion of IT resistance to BYOD is somewhat squashed here with nine out of 10 respondents (according to the results) saying their employees are using their own tech at work.  They found that more Androids are encroaching the workplace; that employees are actually using it for work rather than playing games and that nearly 80% of enterprises will make investments this year to manage consumer technologies.  There’s 7 more myths along with a couple nice graphics to go along with the list.  Interesting and quick read.

When Business and Personal Combine: This Wall Street Journal article talks specifically about the conundrum companies and employees face when a remote wipe comes into play.  What happens, or really, how to deal with situations when there is a fear of a data breach yet wiping the device also deletes all the employee’s personal data, like family pictures.  Policies, use agreements and mobile device management (MDM) solutions are potential solutions.

The new BYOD: Businesses are now driving adoption: Rather than the perils of BYOD, this InfoWorld article talks about how enterprises are starting to actively encourage BYOD, not just passively accept it.  Reporting on Good Technology’s recent BYOD survey, they found that organizations are jumping on the phenomenon sine they see real ROI from encouraging BYOD.  The ability to keep employees connected (to information) day and night can ultimately lead to increased productivity and better customer service.  They also found that two of the most highly regulated industries - financial services and health care - are most likely to support BYOD.  This shows that the security issues IT folks often raise as objections are manageable and there's major value in supporting BYOD.  Another ROI discovered through the survey is that since employees are using their own devices, half of Good’s customers don't pay anything for the employees' BYOD devices – essentially, according to Good, getting employees to pay for the productivity boost at work.

BYOD Is The Challenge Of The Decade:  Europe is also seeing the BYOD trend.  This TechWeek Europe article talks about the familiar threats of malware, spyware, worms and other malicious software but also says that BYOD success depends on both people and technology.  That it’s important to involve management early, consider the legal and financial ramifications along with risks to the business to then make an informed decision about a BYOD plan.  Not sure if it’s the challenge of the decade but it’s a great headline and will continue to fluster IT in the coming years.

IT Security's Scariest Acronym: BYOD, Bring Your Own Device: This PCWorld article uses Nemertes Research data to cover the discrepancies between how companies treat laptops (which can be mobile) and mobile devices themselves.  They both have VPN capabilities and device encryption available but stray in different directions after that commonality.  The obvious difference is laptops are usually IT owned and smartphones are personally owned.  They suggest that it’s a good idea to re-evaluate the difference between security controls on different types of end-user devices and ask, "Is this difference based on valid reasons or a result of legacy thinking?"

BYOD Challenge: How IT Can Keep User-Owned iPhones And iPads Secure In Enterprise: This article looks at both the technical and personal challenges to securing employee-owned devices along with suggestions like user education, cost sharing, purchase assistance, tiered access, reward for enrollment and reward for good behavior.  I like the last one since much of our challenges and much of what I write about is human behavior, the human condition and why we do the risky things we do.

BYOD: Manage the Risks and Opportunities: Bankinfosecurity.com is one of my weekly stops on the internet circuit.  While this article is more a primer for an upcoming webinar, it does offer a number a good questions to ask while considering a BYOD strategy.  They also say that it's no longer a question of whether to allow employees to use their own devices – the questions are now about inventory, security, privacy, compliance, policy and opportunity.

Some BYOD thoughts based on all of the above, in no particular order:

  • Have a BYOD policy or forbid the use all together. Two things can happen if not: personal devices are being blocked and organizations are losing productivity OR the personal devices are accessing the network (with or without an organization's consent) and nothing is being done pertaining to security or compliance.
  • Ensure employees understand what can and cannot be accessed with personal devices along with understanding the risks (both users and IT) associated with such access. What's the written policy and how is it enforced.  Acceptable use.
  • Ensure procedures are in place (and understood) in cases of an employee leaving the company; what happens when a device is lost or stolen (ramifications of remote wiping a personal device); what types/strength of passwords are required; record retention and destruction; the allowed types of devices; what types of encryption is used.
  • Organizations need to balance the acceptance of consumer-focused smartphones/tablets with control of those devices to protect their networks.
  • Organizations need to have a complete inventory of employee's personal devices - at least the one’s requesting access.
  • Organizations need the ability to enforce mobile policies.  Securing the devices.
  • Organizations need to balance the company's security with the employee's privacy like, off-hours browsing activity on a personal device.
  • Personally, I do find that if I’m playing a game at 9pm and an email comes in, I typically read it.

F5 has a number of solutions to help organizations conquer their BYOD fears.  From the Edge Client, to our BIG-IP Global Access Solutions  (BIG-IP APM and BIG-IP Edge Gateway) to the recent MDM partnership announcements, we can help ensure secure and fast application performance for mobile users.

ps

Related or, …and the Rest:

Technorati Tags: F5, smartphone, integration, byod, Pete Silva, security, business, education, technology, application delivery, ipad, mobile device, context-aware,android, iPhone, web, internet, security

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]