A guest post by Gerd Schramm, <data> S, Ulm
iPhone, iPad, BlackBerry, tablet, smartphone—these little helpers have become indispensable in today’s business world. They enable management to stay constantly up to date and give the sales team the ability to always have important business data at their fingertips. Unfortunately, however, these new devices also motivate many data thieves to set up sophisticated traps. Being accessible everywhere also means being vulnerable everywhere. Protecting personal data and sensitive company information is therefore a major challenge today—not only for large corporations but also for small and medium-sized businesses.
Management, employees, and field staff—they all have mobile devices that connect to the company network via mobile networks or Wi-Fi, process internal company data, and store personal information. Every mobile device gives outsiders the opportunity to access important data. Whether it’s a lost smartphone or a virus infection—the data must be protected. Mobile Device Management is essential. If you follow these tips, you’ll be well on your way:
Written guidelines for use:
Establish written guidelines between the employer and the employee. This involves developing individual security policies and company agreements, which are then supported by technical measures. The primary goal must be to create transparency regarding what is and is not permitted. Special provisions must be established if personal devices are to be used for work purposes, or if the personal use of work devices is permitted.
Technical support for the guidelines:
Learn more or get advice: There are a variety of technical solutions available that also offer email security by separating business and personal emails, real-time remote administration and deletion, automatic deletion of sensitive company data in the event of misuse, and location tracking if a smartphone is lost.
Protect yourself from “spy apps”:
Decide from the start how apps will be handled. For example, you can define in advance on a central security server whether to use a blacklist—that is, blocking certain apps—or only a whitelist, thereby allowing only apps that have been classified as permitted. If an employee then installs an app that the company has classified as “critical,” sensitive company data can be automatically deleted from the mobile device.
Follow the law:
Many companies are unaware that they are also violating data protection obligations if a stranger gains access to, for example, a stolen smartphone. Incidentally, even a family member is considered a stranger under the law. But it’s not just data protection laws that must be observed. For example, the Working Hours Act also applies.
About the Author:
< data> S
Whether it’s data protection, information security, secure IT operations, or awareness training—Data S is your trusted partner in the Ulm/Neu-Ulm region for all security matters, because corporate security is a valuable asset and a key factor in successful and sustainable business management.
Data S
Gerd Schramm, Certified Computer Scientist (FH)
Data Protection and Information Security
Sonnenweg 3
89081 Ulm
Tel: 0731/802 36 88
info@data-S-ulm.de
www.data-S-ulm.de