Mobile Device Security (Cybersecurity Month Tip #9)

In many organizations, more and more work is being conducted via “mobile devices” like smartphones and tablets rather than traditional PCs and laptops. The most common of these by far are those running Apple’s iOS (iPhones and iPads) and those running Google’s Android OS. These devices are light, portable, convenient, handy, and generally easy to maintain and manage. However, they are still powerful computing devices that can store a lot of critical information and can also prevent serious security challenges.

Some basic measures that you should take include:
  • Set a password and set your phone to lock automatically after a short period of non-use. It’s so easy to lose a phone on a bus or train or in a restaurant, and if someone picks it up while it’s unlocked they can do and access pretty much everything on the device.

  • Consider enabling a function to wipe the data and settings from your device if the passcode is entered incorrectly enough times. This function does allow for some mischief, however, so be sure you’re backing your device up frequently!

  • Don't "jailbreak" or "root" your device. Doing this will disable many of the built-in safeguards. 

  • Stick with the official "App Store" for your platform. Unlike iPhone, Android makes it easy to allow your device to load apps from elsewhere, just by choosing that option in “settings.” This is NOT recommended, as the VAST majority of Android malware has historically come in apps found outside the Google Play store.

  • Think about the apps you install and use; it pays to research a bit, and to read some reviews and ratings.

  • Enable remote location (e.g. “Find my iPhone”) and remote data wiping services if available for your device.
  • Consider using security software, especially on an Android device.​


In honor of National Cyber Security Awareness Month, for October we will be posting short tips for users on improving their information security awareness and practices every Monday, Wednesday, and Friday all month long.

Comments

Popular posts from this blog

Weekly Infosec News Brief: 14-20 March

Weekly Infosec News Brief 20-26 July

Critical Vulnerability Discovered in IIS 6.0 Web Services