Home > Midmarket IT Security Tips > Security Operations and Strategies > Remote phone lock and GPS tracking counter smartphone security risks
Midmarket IT Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

SECURITY OPERATIONS AND STRATEGIES

Remote phone lock and GPS tracking counter smartphone security risks


Lisa Phifer
07.21.2009
Rating: --- (out of 5)


Midmarket Security Strategies and Tactics
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


According to F-Secure Corp., 10,000 smartphones are reported lost or stolen to the U.K. Metropolitan Police every month. Nonetheless, a recent Credant survey of London commuters found that 40% did not password-protect phones used for business. Large enterprises can afford mobile device managers to enforce passwords and wipe missing smartphones, but how can smaller employers deal with risks resulting from the theft of these convenient little time bombs?

More smartphone
security resources
Three steps to achieve security for smartphones within a budget: Follow these three steps and offset the risks posed by unsecured mobile devices -- and do so within budget.
Find remote mobile device wipe solutions on a budget (Part 2): Several remote mobile device wipe solutions are within the price range of a midmarket company.

CONSIDER ALL REMOTE PHONE LOCK OPTIONS
The first thing to do when a smartphone goes missing is to lock the device, deterring unauthorized access to stored data and applications (e.g., business contacts, email messages, portal logins). Hopefully, that lost device was already locked by an inactivity timer or power-on password. But statistics show that employers who don't enforce mobile device password use can't reasonably assume this is so.

A number of products and services let the administrator and/or user lock a lost smartphone, automatically or upon command. A smartphone may be configured to disable itself:

  • after x-number of failed login attempts,
  • if battery power falls below a designated threshold,
  • if it fails to sync with a designated server after x-days,
  • if its SIM card is removed or replaced, and/or
  • when it receives a specially-crafted SMS or TCP/IP message.

When shopping for an automated or remote smartphone lock, think about who should be able to initiate the lock, under what conditions, and what credentials must be supplied. Do you want the user (and only the user) to invoke this lock through a self-service Web portal, or are you comfortable asking a service provider to lock lost devices for you? How will the device be configured to enable locks so they can be invoked when needed?

Furthermore, it's important to understand the data and applications actually protected by a remote lock. For example, carriers are often able to lock the SIM but not the entire device. Device-resident agents may be able to lock some or all of the data stored on the device, but not all can lock data stored on removable media. When remotely locked, can the device still be used to display a "return me" message or place an emergency call?

Finally, beware that some remote locks are hard to undo or intentionally destructive. If a user reports losing his phone but later finds it, can he simply enter his own password to unlock it again? Or will unlocking the device require an admin or provider-supplied PIN, or even a re-flash and restore?

SMARTPHONE GPS TRACKING FINDS LOST DEVICES
Many lost phones are never returned, but the ability to easily visualize a device's current location improves its chances of recovery. In the past, locating a smartphone wasn't easy. A device in "airplane mode" might never again connect to any network -- LAN or WAN. A smartphone that continues receiving email and SMS messages can be linked to a current IP address, but that tidbit offers little insight into its physical location.

Fortunately, two technology trends are making it easier to find a lost smartphone. First, most new phones support GPS functionality -- when enabled, GPS can supply the device's longitude/latitude. Second, many smartphones now support Wi-Fi -- when active, a wireless IPS or rogue-scanning AP can use triangulation to plot a Wi-Fi client's position inside a building.

Some vendors have already harnessed these technologies to provide geo-location tracking for smartphones. For example, end users can use Apple's MobileMe Find My iPhone service to view the approximate location of any iPhone running OS 3.0 software. IT administrators can use Absolute Software's Customer Center to map the historical and current location of Windows Mobile and BlackBerry devices within 33 feet.

Locationing can aid recovery, but there are still limits. If a lost device is never again turned on, its location cannot be detected. If a thief replaces a lost iPhone's SIM card, it cannot be found by MobileMe. If a smartphone is wiped, its resident agent, radio or GPS may be rendered inoperable. Some countries inhibit use of locationing technologies. Incorporate geo-location tracking within your antitheft arsenal, but learn the restrictions relevant to your workforce.

Lisa Phifer is vice president of Core Competence Inc. She has been involved in the design, implementation and evaluation of networking, security and management products for more than 25 years, and has advised companies large and small regarding security needs, product assessment, and the use of emerging technologies and best practices.

Send comments on this technical tip editor@searchmidmarketsecurity.com.

Join our IT Knowledge Exchange discussion forum; please use the midmarket security tag.


Rate this Tip
To rate tips, you must be a member of SearchMidmarketSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Security Operations and Strategies
Five things to do before your first PCI DSS compliance audit
How to detect malicious insiders by monitoring antivirus log files
Take four steps toward Macbook security
How to maintain network control plane security
Four things to remember about server virtualization security concerns
How to choose online data backup services for data protection
Validate your perimeter network security devices are working
How to choose an external compliance auditor
PCI DSS: Writing an information security policy
How to choose full disk encryption for laptop security, compliance

Wireless network security management
Find remote mobile device wipe solutions on a budget
Avoid security risks of Free Public WiFi wireless ad hocs
Five steps to eliminate rogue wireless access
Three steps to achieve security for smartphones within a budget
Real-world best practices for securing remote offices
How to set up a UTM firewall to secure a remote office
Quiz: Securing your first remote office
Safe but simple wireless authentication
Choosing midmarket wireless authentication server infrastructure options
How to build a secure wireless connection

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts