Customize Consent Preferences

We use cookies to help you navigate efficiently and perform certain functions. You will find detailed information about all cookies under each consent category below.

The cookies that are categorized as "Necessary" are stored on your browser as they are essential for enabling the basic functionalities of the site. ... 

Always Active

Necessary cookies are required to enable the basic features of this site, such as providing secure log-in or adjusting your consent preferences. These cookies do not store any personally identifiable data.

No cookies to display.

Functional cookies help perform certain functionalities like sharing the content of the website on social media platforms, collecting feedback, and other third-party features.

No cookies to display.

Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics such as the number of visitors, bounce rate, traffic source, etc.

No cookies to display.

Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.

No cookies to display.

Advertisement cookies are used to provide visitors with customized advertisements based on the pages you visited previously and to analyze the effectiveness of the ad campaigns.

No cookies to display.

Categories
Articles

ENISA Guide to Risk Mitigation for BYOD

ENISA have published a useful set of controls and best practices for managing the risks in a Bring Your Own Device (BYOD) program. They identify three groups of controls

  • Governance
  • Legal, Regulatory and HR
  • Technical (Device, Application, User and Data)

Throughout, the focus is on the owners, not the devices, which seems right. If the owners don’t understand the need for behavioural and technical controls and aren’t provided with the skills and motivation to follow them, then with full control of the device they can ignore or override them anyway. For example it may be cheaper and more effective to support staff in appropriate use of social networking tools rather than to try to impose software on all their devices to prevent loss of business information. BYOD programs should therefore be voluntary, with owners making a positive choice to share their devices with their organisations, understanding and accepting the responsibilities that brings.

There are some interesting ideas on how to encourage participation in the programme, including provision of support, offer of additional services, or even financial benefits! It strikes me that at least the first two have beneficial side-effects for the organisation too. Making things work well for those who participate in the official scheme may bring into the fold those who would otherwise try to connect their devices unofficially (I remember universities achieving successful deployment of quality wifi by a similar technique). Providing or recommending services such as webmail and storage means that the organisation can direct users to options that satisfy the security requirements of both users and the organisation.

There are interesting ideas on keeping organisational and personal use separate, not just in technical terms but also in policy. An explicit policy that organisational support staff and management software will only look at organisational data and applications should help staff/owners trust that their privacy is being respected and encourage them to respect the organisation’s interests in return.

Finally there’s a recognition that this is a very rapidly changing area where new technologies and practices quickly move from brand new to completely routine. Organisations need to work with their staff to incorporate BYOD into their existing systems for managing information security to ensure this is done in a way that benefits both.

By Andrew Cormack

I'm Chief Regulatory Advisor at Jisc, responsible for keeping an eye out for places where our ideas, services and products might raise regulatory issues. My aim is to fix either the product or service, or the regulation, before there's a painful bump!

Leave a Reply

Your email address will not be published. Required fields are marked *