Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Managing BYOD Security Without Alienating Users
Articles

Managing BYOD Security Without Alienating Users

ISBuzz TeamBy ISBuzz TeamAugust 14, 2014Updated:August 14, 20145 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
byod
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The trend for individuals to bring their own device to work is increasing, but enabling BYOD has been much easier than understanding and managing its security implications.

In many instances, increasingly tech-savvy users are simply configuring their own remote and email access outside corporate IT security guidelines and potentially storing sensitive corporate information on them. This introduces issues where users might bring their own device into the office and then connect it to the corporate network using a wired or a wireless connection.

I believe we need to find practical ways to support consumer technology at work while maintaining control of sensitive information. BYOD requires a security policy which is enforceable, realistic, acceptable to users and doesn’t violate personal privacy laws. It needs to ensure there is no ambiguity and that all users are clear what is and is not allowed. Once all employees have been informed, the policy should be rigorously enforced.

Whoever is responsible for company IT should also encourage users to come to them for advice on using their device so that they don’t send information outside the organisation in an uncontrolled fashion.

The core principle is to minimise the amount of data transferred to or held on the device. There are three steps organisations can take:

1.) Virtualise applications and stream them to the device.
2.) Allow access but implement a corporate policy to prevent the user downloading sensitive organisational data. If the organisation wants to allow data to be downloaded, it becomes the user’s responsibility if they lose the device, and they need to be made aware of the consequences and their responsibilities.
3.) Take advantage of the remote wipe capability that most devices have, using encryption to secure sensitive data, and ensure that the organisation’s BYOD policy mandates implementing Mobile Device Management (MDM) capability on the device.

Virtualisation can be enacted in three ways. Option one is to run a hosted or virtual corporate desktop which the user can access through their device using software such as Quest, Citrix or VMware. All the device needs is the appropriate client software. This solution is largely device-independent, so it will work with everything from a user’s own laptop and all major tablet types to a Windows, Android or Apple phone. It does need appropriate back-end systems and network connectivity to deliver the desktop or application, which means that the user cannot work on corporate applications unless they are connected to the network. It can also be set up so the user can only access the desktop from known IP addresses. Of course, ensuring that the device is reasonably secure and protected by some form of security software is important.

A second option, particularly for laptops, is to install client hypervisors and virtual desktop check-in/check-out software on the device, such as MokaFive, Citrix Xenclient or VMware View offline. Windows 8 HyperV can also work in a similar fashion. This is a higher impact solution as the IT team needs to configure the user device and install the client hypervisor to accept the virtual desktop. It works by creating separate, bootable desktops on the same device and partitioning the hard drive into business and personal areas. As this can be run locally, it’s a good solution if the user needs to work offline. When they go back online it checks back into the server (using a VMware/Citrix solution) or synchronises (using MokaFive/Quest). It’s particularly good with laptops but won’t work with all devices as you cannot run a full corporate desktop on devices such as an iPad. It also creates more work for the IT team, who have to configure the device and install the client hypervisor to accept the virtual desktop.

The third option is to repackage applications to be accessed through a portal (similar to iTunes). It requires either application streaming or the creation of lightweight clients (apps) which can run on a smartphone or tablet, devices which have just enough intelligence to run basic functions while most of the processing is carried out by the web-based back-end. This becomes more difficult if the user wants to run ‘large’ applications such as SAP or Microsoft Office. This is where most people believe desktops are heading, with a web portal used to display available applications to the user accessible from a wide range of devices and operating systems.

BYOD is clearly here to stay, so each organisation needs to find a way to develop a policy that both maintains data security and satisfies users. The list of considerations will differ for each organisation, but it is always essential to ensure that corporate policy is made first before looking for technical solutions.

By Richard Blanford, Managing Director, Fordway

richard_blanfordBio: Richard founded Fordway in 1991 and has built it into one of the UK’s most respected IT infrastructure change providers. An ex-technician, his 20+ years’ experience enable him to prioritise business-critical problems and offer constructive, vendor independent advice.

Aiwatch__Banner_Article

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}