THANK YOU FOR SUBSCRIBING
Enterprise Security Magazine | Tuesday, September 10, 2019
BYOD has become a popular trend among enterprises. However, how can CIOs cope up with the security risks of BYOD?
FREMONT, CA: BYOD (Bring your own device) is a business policy that gives its employees the authority to use their own devices such as smartphones, tablets, and laptops, to work with company systems, networks, software, or information. In this approach, the company agrees to support the employees' personal devices or sometimes give them stipends to purchase one.
BYOD is a part of the consumerization of IT, where workers are extremely attached to the devices. Doubtlessly, BYOD accelerates the productivity of the company, simultaneously boosting employee morale. It also enables the company to save money and time as there are zero requirements of giving any training to the employees regarding their own devices. Hence, it reduces operating costs as well. It also leads to the higher appeal of the organization when it comes to retaining the old employees as well as hiring the new ones.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
However, benefits come along with increased security threats. Since organizations have less control over the BYOD devices, there is an increased risk of data breaching. Troubleshooting can be another issue for the companies using the BYOD approach.
To cope with such threats, it is necessary to design a strong BYOD program. Following are some of the tips to secure the devices and reduce BYOD threats:
1. Control over application access: Since most of the devices already have access control features embedded in it, it becomes mandatory for the business IT and security teams to assist the employees in augmenting their access control and application permission settings. This enables each app to access what it really requires to function.
2. Enrolling 'Find my Device': Every BYOD device should be linked to a device locator service. In case, any device is lost, the services possess the ability to track that device or wipe the device remotely. This measure of wiping the device is kept as a last resort if the device is lost or stolen.
3. Using Mobile Device Management (MDM) software: No doubt, many IT and security teams are making use of MDM software as this enables them to implement software configurations and security settings on all the devices that are linked to company networks.
4. Using password secured access controls: Setting the password for BYOD device should be the first critical step. Many employees choose to ignore keeping any password or access PIN to secure their devices. This makes their devices more vulnerable to the threats. The passwords should be unique and difficult to guess for every account or device.
5. Updating OS, software, firmware, and other applications: The organizations, as well as the employees, should always ensure that all their devices' OS and other software are up-to-date. This is a crucial step as the software updates contain new security features for protecting the employees for dangerous risks, exploits, and threats.
6. Avoiding personal financial data to be stored on the device: Employees should never store their personal, financial, or other sensitive data on their devices. This precaution is needed in the event of the lost, stolen, or a compromised device.
7. Control on service connectivity and wireless network: Bluetooth and wi-fi connectivity should be switched off when no one is using, or the organization should find some trusted networks for the device connectivity. Devices should be connected when the employee is actively working; otherwise, there are high chances that the worker might unknowingly connect the device to some unsafe networks.
8. Installing mobile antivirus software: There are many antivirus and security applications commercially available in markets that are solidly built to protect the devices from threats. Enterprises should assist their workers in choosing the right antivirus software for their devices before they start using the devices at work.
9. Device Data Back-Up: It is vital for all the organizations as well as their employees to periodically backup their devices' data. Backing up of device data in addition to the security and recovery process reduces the damage if the device is stolen or lost.
10. Beware of free applications: It has been found that many free apps track their users' or share the data of their users with advertisers or third parties. Organizations should look deep into the apps before giving them permission to install on the BYOD device or download only from trustworthy publishers. IT and security teams can also provide the employees with the list of applications that they can install.
Though the BYOD approach has been very fruitful for the enterprises, the CIOs should also keep in mind the mitigation strategies to avoid turning the successful BYOD implementation into a bug-ridden security nightmare.
More in News