SANS Technology Institute - Candidate for Master of Science Degree Design Phase 1 of an iPhone Rollout Mark Baggett, Jim Horwath June 2010
SANS Technology Institute - Candidate for Master of Science Degree Overview Business benefits of iPhone Biggest risk of iPhone usage Risk in current infrastructure Options to mitigate risks Recommendations
SANS Technology Institute - Candidate for Master of Science Degree Business Benefits Company viewed as an innovator and leader Allow the organization to respond to an increasing mobile world Faster response to market information
SANS Technology Institute - Candidate for Master of Science Degree Risk of Mobile Devices RiskMitigation Sensitive data on lost or stolen devices -Device on data is encrypted -Password protect devices -Remote wipe of device Malware (Viruses, worms, & backdoors) Control the installation of software from untrusted sources Rouge or untrusted devices connecting to, and storing company data Device authentication
SANS Technology Institute - Candidate for Master of Science Degree Risks in Current Infrastructure By default Microsoft Exchange 2003 and later allows any “ActiveSync” enabled mobile device to download Recommend immediate action be taken Open issue regarding the handling of devices that currently have company data on them
SANS Technology Institute - Candidate for Master of Science Degree Mitigation Strategies Apple iPhone Configuration Utility implements most password controls Microsoft Exchange Mobile Device Manager implements the ability to “Wipe” a device remotely 3rd Party products are available to implement the remaining controls
SANS Technology Institute - Candidate for Master of Science Degree Recommendations Current BlackBerry level of security is not achievable using manufacturer provided software GIAC should evaluate 3rd Party software options We have a short list of products that claim to fully mitigate those risk