Today's Top Stories Need help assessing the strengths and weaknesses of commercial mobility platforms for your enterprise but can't bear the expense of hiring a consultant or purchasing a pricey analyst report? Look no further than our friends across the pond. The United Kingdom's Communications-Electronics Security Group, the central government agency that serves as the country's technical authority for information assurance, publicly released a suite of documents that could greatly benefit enterprise CIOs. The agency issued documents detailing security guidance for the following mobile platforms: > Android 4.2 > Samsung devices with Android 4.2 > BlackBerry 10.1 (EMM Corporate) > BlackBerry 10.1 (EMM Regulated) > Apple iOS 6 > Windows Phone 8 Each platform is assessed against 12 security recommendations, including authentication, application whitelisting, device update policy and assured data-at-rest protection. The platform-specific reports also recommend methods CIOs can employ to satisfy these security recommendations should a platform fall short in a given category. The virtual private network is one significant risk of using Android 4.2, say report authors. The VPN on the platform has not been independently assured to "foundation grade" and it doesn't support some of the UK's requirements of assured VPNs (.pdf download). "Without assurance in the VPN there is a risk that data transiting from the device could be compromised," according to the report. A chief concern when using Apple iOS 6 is that applications must opt-in to the various data encryption classes on a per-file basis--with the exception of its mail app. "Files other than e-mail and attachments will not be encrypted when the device is locked, and could be extracted without knowledge of the password, using a vulnerability in the platform," write report authors. BlackBerry 10.1--both corporate and regulated--does not have dedicated hardware to protect its keys. "If an attacker can get physical access to the device, they can extract password hashes and perform an offline brute-force attack to recover the encryption password," says the report authors. The extensive per-platform reports detail many considerations for enterprises allowing their workforce to use these devices. Among other takeaways from the reports--15 in all published Oct. 14--is the conservative advice that UK government agencies avoid allowing employees to bring their own device at all. The agency argues that device management must be applied at the time of provisioning to ensure a "known good" state before accessing the network. This scenario is extremely rare in the case of BYOD because "provisioning" is when an employee purchases his personal smartphone or tablet. For more: - go to the CESG device security guidance landing page Related Articles: Encryption flaw in WhatsApp could allow attackers to decrypt messages Nearly two-thirds of organizations do not enforce encryption policies, says analyst Firms mull self-destructing data apps Read more about: United Kingdom, Android 4.2, BlackBerry 10.1 back to top | This week's sponsor is Moovweb. |  | Webinar: 8 Ways to Unify Your Web, Mobile & Apps Strategy Wednesday, November 20th, 2pm ET / 11am PT Companies can now unify their web, mobile and apps strategy with a single platform approach, saving time and money, and freeing up resources to focus on delivering incremental business value. Tune in to this webinar to see real life examples by Moovweb. Register here today. | Identity management software maker Centrify is launching a new partner program providing developers, cloud and mobile independent software vendors--ISVs--the tools to jointly build integrated solutions allowing customers secure access to mobile and cloud applications. The Centrify Alliance Partner Program enables partners like Dropbox and Zoom to address joint customer demands in the software-as-a-service and mobile device management markets. For example, CAPP partners may support the Centrify Mobile Authentication Services software development kit to provide customers with Centrify's Zero Sign-on validation solution across their mobile apps. There are also more than 2,000 cloud applications integrated with Centrify providing single sign-on and role-based access control, the firm said. In addition, CAPP partners are given access to Centrify training, licenses and publications--as well as joint development and integration testing--and sales and marketing resources. Developers and ISVs can choose between three levels of Centrify CAPP partnerships. The Developer Partner level provides cloud and mobile developers with a free solution for integrating their apps with the Active Directory-based Zero Sign-on. Developer Partners also receive discounts on Centrify products, services and support and obtain access to Centrify APIs. The CAPP Business Partner level touts SaaS, mobile and Mac solutions--including single sign-on and mobile container, application and device management tools. Centrify also works with partners to implement joint marketing and sales strategies, including opportunities to cross-sell, upsell or promote solutions to Centrify customers. The CAPP Premier Partner level employs Centrify's strategic partnerships with technology allies. According to Centrify, its premier partners have proven success in cross-selling and recommending its products globally and this program level offers access to Centrify's customers for mutual benefit. For more: - read this release Related Articles: IT service providers put mobility money where their mouths are Gartner: CIOs ready to invest in more mobile tech Cloud-based commercial fleet telematics units to reach 16.8 million by 2018 Read more about: Mobile Device Managment back to top Samsung Electronics released a new software development kit enabling developers to build applications leveraging its Knox mobile enterprise security software platform. The end-to-end Knox solution provides security hardening from the hardware to the application layer on selected Samsung devices running Google's Android. Knox uses application container technology, allowing IT departments to support both BYOD and corporate-liable models while reducing the risks to corporate security or employee privacy. The Knox SDK lets developers access protocols like a customizable secure boot and ARM TrustZone-based integrity measurement architecture. Speaking Monday at the Samsung Developers Conference in San Francisco, Injong Rhee, Samsung's senior vice president and head of technology strategy and the enterprise, said the platform will support fingerprint sensors and other sensor-based safeguards in the future. "This is not rocket science, but it is darned good computer science," Rhee, who launched the Knox group three years ago, was quoted by the EE Times as saying. Earlier this month, Samsung reached an agreement to integrate NQ Mobile's NQSky mobile device management platform into Knox. NQSky provides enterprise mobility services like mobile data strategy consulting, architecture design and deployment and mobile device content and application management. Samsung will leverage NQSky to strengthen device management and security protection across Knox-enabled products. Enterprises may also use the platform-agnostic NQSKy to manage employee access across rival Android devices as well as iOS and Windows Phone. The Google-led Android mobile OS is under attack by more than a million malware threats and high-risk applications, according to data issued by security software firm Trend Micro. Seventy-five percent of questionable apps identified by Trend Micro perform outright malicious routines like sending messages to certain numbers and registering users to costly services while the remaining 25 percent exhibit dubious routines, including adware. For more: - read this release - read this EE Times article Related Articles: Samsung teams with Lookout to beef up Android phone security Google boosts BYOD management features for Android devices Report: Samsung to delay release of KNOX security platform until summer Galaxy S4 is first Samsung smartphone with KNOX enterprise security technology Read more about: Android 4.0, Knox back to top |
No comments:
Post a Comment
Keep a civil tongue.