<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Smart@Work &#187; Mobile Security</title>
	<atom:link href="http://mobileiron.com/blog/category/mobile-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://mobileiron.com/blog</link>
	<description>The human, business, and technology impact of smartphones in the workplace</description>
	<lastBuildDate>Thu, 01 Jul 2010 00:16:54 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>A Matter of Trust</title>
		<link>http://mobileiron.com/blog/2010/06/a-matter-of-trust/</link>
		<comments>http://mobileiron.com/blog/2010/06/a-matter-of-trust/#comments</comments>
		<pubDate>Thu, 01 Jul 2010 00:16:54 +0000</pubDate>
		<dc:creator>ojas</dc:creator>
				<category><![CDATA[Mobile Security]]></category>

		<guid isPermaLink="false">http://mobileiron.com/blog/?p=248</guid>
		<description><![CDATA[Had a very interesting conversation this week about the evolving trust model for mobile security in the enterprise.  I was talking to Terry R, who focuses on risk management and compliance, and he was telling me how his company’s perimeter security strategy needs to fundamentally change. 
As he put it:  “Our challenge is that our infrastructure, [...]]]></description>
			<content:encoded><![CDATA[<p>Had a very interesting conversation this week about the evolving trust model for mobile security in the enterprise.  I was talking to Terry R, who focuses on risk management and compliance, and he was telling me how his company’s perimeter security strategy needs to fundamentally change. </p>
<p>As he put it:  “Our challenge is that our infrastructure, applications, and databases are designed for a perimeterized world.  Our systems rely on a strong perimeter.  We need to tear that perimeter down.”</p>
<p>The catalyst for the conversation was smartphones, which operate almost constantly outside the perimeter.  Since the perimeter is no longer “reliable”, security becomes a matter of trust.  Which device do I trust with which data for which user under which circumstance?  The same questions, certainly, as existed before smartphone adoption.  But the answers are now <span style="text-decoration: underline;">much</span> more difficult to pin down.  The trust model for mobile is a rapidly moving target.  New operating systems appear every year.  New devices appear every week.  New consumer apps appear every minute.  And end-users constantly set and change the debate.</p>
<p>How does a security team keep up?  The more rigid ones will likely fall behind.  The nimble ones will adopt a flexible mindset that can trade effectively between security and privacy, usability and control.  Protecting enterprise data without compromising end-user experience will be the goal.  A dynamic but rational model of trust that can operationalize the model below will be one of the important tools.</p>
<p><a href="http://mobileiron.com/blog/wp-content/uploads/2010/06/Identity-Access-Management.jpg"><img class="alignnone size-medium wp-image-249" title="Identity  Access Management" src="http://mobileiron.com/blog/wp-content/uploads/2010/06/Identity-Access-Management-300x225.jpg" alt="" width="300" height="225" /></a></p>
<p>(Thanks, Terry, for the ideas behind this post)</p>
]]></content:encoded>
			<wfw:commentRss>http://mobileiron.com/blog/2010/06/a-matter-of-trust/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>My Phone, Your Headache</title>
		<link>http://mobileiron.com/blog/2009/10/securing-employee-owned-smartphones/</link>
		<comments>http://mobileiron.com/blog/2009/10/securing-employee-owned-smartphones/#comments</comments>
		<pubDate>Sat, 17 Oct 2009 02:45:25 +0000</pubDate>
		<dc:creator>ojas</dc:creator>
				<category><![CDATA[Mobile Security]]></category>

		<guid isPermaLink="false">http://mobileiron.com/blog/?p=168</guid>
		<description><![CDATA[Network World runs the Insider Threat column bi-weekly and gave us the opportunity to contribute to today&#8217;s column.  You can find the column on the Network World site at http://bit.ly/3gPlQp .
Existing models for smartphone management take a very one-way approach to security.  IT ends up being the police force and it&#8217;s a role that is not [...]]]></description>
			<content:encoded><![CDATA[<p>Network World runs the Insider Threat column bi-weekly and gave us the opportunity to contribute to today&#8217;s column.  You can find the column on the Network World site at <a href="http://bit.ly/3gPlQp">http://bit.ly/3gPlQp</a> .</p>
<p>Existing models for smartphone management take a very one-way approach to security.  IT ends up being the police force and it&#8217;s a role that is not scalable, especially since users are reticient to give up control of their phone to begin with.  Employee-owned phones just make the problem worse.</p>
<p>The central theme of the column is that responsibility needs to be shared in order for behavior and data to be secured.  This model of Cooperative Security requires both a change in mindset and policy, plus access to tools that support both.</p>
]]></content:encoded>
			<wfw:commentRss>http://mobileiron.com/blog/2009/10/securing-employee-owned-smartphones/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Setting Boundaries</title>
		<link>http://mobileiron.com/blog/2009/08/setting-enterprise-data-boundaries/</link>
		<comments>http://mobileiron.com/blog/2009/08/setting-enterprise-data-boundaries/#comments</comments>
		<pubDate>Sun, 23 Aug 2009 04:49:41 +0000</pubDate>
		<dc:creator>ojas</dc:creator>
				<category><![CDATA[Mobile Security]]></category>

		<guid isPermaLink="false">http://mobileiron.com/blog/?p=151</guid>
		<description><![CDATA[I’m sitting on a plane right now.  Center seat … jam packed.  Guy on my left is asleep.  Guy on my right wants to talk way more than I do.  I don’t so much mind Left-Guy except when his head ends up on my shoulder.  But Right-Guy is getting into my personal space and it’s [...]]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal" style="margin: 0in 0in 0pt;">I’m sitting on a plane right now.  Center seat … jam packed.  Guy on my left is asleep.  Guy on my right wants to talk way more than I do.  I don’t so much mind Left-Guy except when his head ends up on my shoulder.  But Right-Guy is getting into my personal space and it’s bugging me.</p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"> </p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;">Back in corporate-land, there is no personal space.  Companies are very clear that all communication on company networks / devices is company property and the employee should have no expectation of privacy.  For legal reasons that needs to extend to employee-owned devices being used for corporate work as well.</p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"> </p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;">But as an employee, that grates me.  It’s my phone and I really don’t want my employer to have access to my pictures, videos, ringtones, and [yahoo/g/hot/other]mail.  I need a data boundary that I know will be respected in all but the most exceptional situations. </p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"> </p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;">Companies are realizing this too.  <a href="http://twitter.com/hyounpark_AG">@hyounpark_AG</a> at Aberdeen Group has early data that says 20% of companies allow all employees to use personal devices.  That’s actually a staggering number.  The implication is that the need to set <strong>enterprise data boundaries</strong> is a problem of the present, not just the future.  Employers needs to protect corporate data and ensure compliance while respecting employee’s personal content.</p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"> </p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;">But what boundary should my company set?  Is this type of flexibility a boon to employees or a bane to legal?   </p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"> </p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;">True, it’s a question of both policy and technology, but I think most importantly it is a question of <strong>end-user satisfaction</strong>.  If you have employee-owned phones, your users need a good answer.  That answer might vary company to company but, like my Left-Guy / Right-Guy problem, it can’t be ignored. </p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"> </p>
]]></content:encoded>
			<wfw:commentRss>http://mobileiron.com/blog/2009/08/setting-enterprise-data-boundaries/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
