Network Computing is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them. Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Smartphone Security: How To Manage Rogue Mobile Devices: Page 4 of 7

  • Don't forget to have users change passwords every 30 or 60 days.
  • Make sure the device is set to engage the password for log on or sign on. Set it at a reasonable time, such as 5 minutes.
  • Give the employee time to get things done, and perhaps go back to their smartphone without having to re-key the password every time they touch the smartphone. This one is a little bit of a two-edged sword, however. One of the top reasons for calls to IT is to get forgotten passwords. Be prepared to trade some IT support time for this added measure of security.

Block Removable Storage: Mass storage in the form of CF, SD or microSD cards is cheap and easy to remove from an unattended smartphone. Security tools can prevent even authorized users from downloading files or other data to removable storage. You can also choose to enforce encryption on removable storage if it is necessary that employees be able to transfer files back and forth. This way, only approved corporate devises can decrypt the information and access the files.

Educate Employees: Employees need to understand what is at risk. It does no good to enforce all sorts of policies that employees feel are simply onerous Big Brother-like controls. If they don't believe security is important, they might be tempted to skirt the rules. Conducting seminars that highlight the dangers of mobile technology is one way to help convince people that there's something more at stake than simple embarrassment. Some companies require employees to be responsible for lost or stolen hardware. What if their culpability extended to the information lost on such devices? That might force them to be a bit more careful.