Wolfram Funk: As a rule, there are persons in the United States who deal with these risks. This is often the responsibility for information security or IT-affine employees. Sometimes, however, the topic also boils up in the disciplines.
Mr Funk, do American companies correctly assess the risks arising from the business use of smartphones?
The media, as well as providers of security solutions, are a major contributor to the general awareness of mobile risks in American companies. Unfortunately, comparatively few companies manage to assess the actual risk in the house. This often fails because of the lack of inventory of mobile deployment scenarios. In addition, there is also no archived history of incidents that could be included in a risk assessment. The bottom line is that in some companies, mobile security is discussed much, but concrete investment decisions are pushed to the long bank due to other priorities. In addition, decision-makers of the "user-friendliness" of smartphones often measure a much higher weight than the security, for example in the topic of "PIN lock."
What makes smartphones dangerous for American companies?
Wolfram Funk: Smartphones now support a growing number of business processes. As a result, the information "treasury" of companies is increasingly vulnerable via smartphones. This development has contributed greatly to the development of the malware industry and is also attractive for targeted hacking of devices and apps - especially as more mobile solutions are deployed on standardized operating systems such as Android and iOS.
What are the differences in risk assessment with regard to company size?
Although smartphones are all-rounders today, they do not last long in the standard configuration of experienced attackers. At the same time, more and more companies also allow the use of external apps within certain limits, which are not developed on their own behalf. These initially untrustworthy apps provide on the device for risks such as data leaks, manipulation of data as well as the removal of important mobile services. In addition, companies are often not consistent with working on guidelines and standards for mobile security. The documents are often incomplete. Moreover, the available mobile security technology options are still intransparent and
How can American companies regain control of their communications systems?
Awaken false expectations, and the processes for managing and deleting the devices are often incomplete.
Wolfram Funk: Small and medium-sized enterprises are trying to create security and cost-efficient management for a growing number of smartphones. The keyword is "mobile device management", and the initiatives are very product centric. The IT managers are the driving force here, even if they are always braked by the financial responsibility and their sparzwang. Larger companies, on the other hand, have recognized that overarching mobile strategies must be developed to meet the requirements for endpoint, app and middleware architectures as well as for the development of secure mobile applications.
Often, they have also developed detailed bottom-up approaches for mobile security in individual areas, even if they often lack central policies and concepts.
Wolfram Funk: First, the growing number of mobile devices should be managed centrally. This allows an adequate safety level to be achieved while at the same time cost-effective operation. Therefore, companies can hardly ignore a standardization of devices and safety measures. Secondly, it is important to take safety into consideration when developing mobile strategies from the outset. For example, guidelines are to be formulated so that software developers know the guard rails for secure app development. The superior architecture is just as important. For example, the question of how the application development interfaces (APIs) are provided to the developers.
Thirdly, sensitive business data must be carefully protected against unwanted access by third-party apps. This is already possible with whitelisting or foreclosure approaches, even if the devil is in the detail. Information security officers today should actively contribute to these three target areas within their company. Otherwise, individual departments and business units, but also the IT organization, create their own facts - these can lead to unpredictable risks and wrong investments.
No comments:
Post a Comment