Showing posts with label BYOT. Show all posts
Showing posts with label BYOT. Show all posts

Wednesday, April 15, 2015

Verizon: Mobile Security Is a Back-Burner Issue for Now


As reported on CNET, enterprises should devote fewer resources to securing their mobile infrastructure, since it is less prone to attacks, Verizon Communications advises in its 2015 Data Breach Investigations Report. The telecom does expect mobile security to become more of a major issue once companies improve efforts in areas where hackers are more apt to invade.
 

Friday, May 3, 2013

Infosecworld 2013

Last week was Infosecworld. Not surprisingly, as in 2012 the main topics were Big Data, BYOD, mobility and cloud security, and risk. Jeff Crume had several sessions on access control and identity management, including Federated identity management and single sign-on. It’s interesting to think that the big social networking sites—Facebook, Twitter, LinkedIn, Yahoo—use Federated identity. Now, I can log into Yahoo mail using Facebook or Google, not that I want to do it. I’m not sure whether this is good or bad, but it is interesting that while this is being discussed within the enterprise, the social world went ahead and implemented it. Of course, the security and privacy concerns are vastly different between the two worlds.
I heard a lot of talk about cyber espionage, both in sessions and in keynotes. Also, that the defensive focus has changed from cyber crime to cyber espionage and warfare. Of course, APT came into the discussion, although there was some disagreement about what it was. There was even a demo session on hacking SCADA, ICS, programmable controllers, etc.
Jay LaRosa and a colleague from ADP gave an interesting presentation on its next-generation security management platform system. It integrated passive data access network, SIEM, GRC tools, and massively scalable data warehouse; added advanced threat modeling, and provided real-time analysis and reporting. I recall from an earlier presentation about SEIM that between hardware, software, and personnel requirements it was out of reach of most places.  This presentation confirmed that observation, but it is a very impressive system.
BTW, I still need proposal for books on DLP, SEIM, BYOD, APT.  


Thursday, May 10, 2012

Just Say No?

It wasn't easy to do when Nancy Reagan wanted kids to reject peer-pressure to try drugs, and it's apparently even harder to say no to users intent on BYOD.

The same people who want to create more security threats now want more security. I wonder what they'll think about more security when it'll require installation management software on their digital toys, and maybe have to submit to intense awareness training?

Friday, February 17, 2012

Developers say Apple needs to overhaul iOS user information security; jailbreak apps access user data far less frequently than Apple-approved apps in the App Store

There are really two stories here. One is the continuing litany of security-challenged apps for various personal devices. Surely, a threat for getting BYOT under control. The second story concerns a reference to a study that determined that jailbreak apps are more secure than the approved apps sold on the Apple store. As Col. Klink would say, "Very interesting."

Monday, January 30, 2012

BYOD, BYOT, IT Consumerization: A Burning Issue

I've been beating the bushes looking for someone to pen a book on BYOD, without success.

Sometimes I think I have a hard time separating media and conference hype--the need to cover something and create some level of FUD--and reality, or what people in the trenches think. Frequently, media-generated FUD is backed up by survey data, which may or may be valid, fueling the fire.

So, not I ask, "Is BYOD, BYOT, IT consumerization, or whatever you call it really a burning issue?