I've written many times about the Bring Your Own Device movement (BYOD) and the need for increasing security controls.
For years, we've controlled device settings on Blackberry devices with the Blackberry Enterprise Server (BES). We force passwords, encryption, and device memory wipes for ten failed passwords so that every user has enterprise enforced security
With iPhones and Android devices it's harder to control settings and behavior on personal equipment.
We think the best we can do within the limitations of present server-side technology is to enforce the use of passwords on all devices using Active Sync, require a timeout of 10 minutes, and eliminate the use of the most simple passwords (1234, 1111 etc). Microsoft Exchange/Active Sync can query the device for the settings currently in place and only synchronize email if the device adheres to enterprise security policies.
We'll eliminate support for POP and IMAP protocols because these cannot be used to inspect and enforce desirable device settings.
We've debated the use of settings that automatically wipe the device for 10 failed password attempts, as we do with Blackberry. However, given that we cannot selectively purge corporate verses personal data, we'll likely avoid that setting for now.
BYOD management is a journey. Server side tools that inspect personal devices and only allow synchronization of corporate data such as email when settings are consistent with policies seem like a cool solution.
In the future, we may add client software (Mobile Device Management) to each device to provide more control over encryption on Android devices and permit selective memory wiping of corporate data.
I welcome comments on what others have done. BYOD is here to stay. Compliance and IT departments need to collaborate on a set of policies and technologies that will meet the needs of regulatory requirements while maintaining service capabilities and user productivity.
Friday, May 11, 2012
3:00 AM
dssadsds
No comments
Related Posts:
The Stage 2 Standards and Certification NPRMOn Friday, ONC released the Standards and Certification NPRM, the companion to the the CMS Meaningful Use Stage 2 NPRM.Here's a bookmarked PDF - thanks to Tony Panjamapirom of the Advisory Board.In my view, the NPR… Read More
A First Look at Meaningful Use Stage 2The Meaningful Use Stage 2 Notice of Proposed Rulemaking was released today at 4:15pm. It represents the work of hundreds of people from every healthcare stakeholder group. I'll summarize all 455 pages this weeke… Read More
Lessons Learned from ChinaOn Sunday I returned from a week in Shanghai and Hangzhou. A remarkable trip that included daily meetings with government, academic, and clinical leaders. What did I learn?In China, about 5% of the GDP is spent … Read More
S&I Framework Implementation GuidesNow that the Stage 2 Standards and Certification NPRM has been released, many people are asking me for the detailed implementation guides that will support it.The S&I Framework website is being enhanced to make their work… Read More
Our Cancer Journey (Week 10)Kathy is now finished with the hardest part of her chemotherapy regimen, Adriamycin/Cytoxan. Next week, she begins Taxol every week for the next 12 weeks. Taxol is typically far less fatiguing than AC. &nb… Read More
Subscribe to:
Post Comments (Atom)
0 comments:
Post a Comment