Showing posts with label Mobile Solutions. Show all posts
Showing posts with label Mobile Solutions. Show all posts

Friday, October 19, 2012

IBM Business Partner, ZSL Incorporated Develops with Worklight





ZSL, IBM Business Partner, talks about ZSL's capability to develop secured cross-platform mobile app with reduced development cost using Worklight.



Mobile Business Partner video


Tuesday, October 16, 2012

Do’s & Don’ts for BYOD and COPE Mobile Users

Businesses are going mobile one way or the other. Employees prefer to carry their personal modern mobile devices such as Smartphones and Tablets to work because of their ease of use and availability. On the other hand, enterprises introduce corporate owned mobile devices to gain pre-established security as in the desktop era. In either case it is evident that these modern devices have changed the personal lives of people in many ways from storing and sharing photos, personal information, social media networking and more. So, people wanted to use the mobile technology that transformed their personal lives in the work place. So also, enterprises visualize many benefits of leveraging mobility into their businesses like the increase in employee productivity, satisfaction, responsiveness, rapid reach of information and more. Employees feel more content with the freedom to use the mobile devices of their choice. Also, with the greater degree of ownership and personal finance involved, they take time to maintain their beloved gadgets.       
Mobile users are of two groups: Bring Your Own Device (BYOD) users and Company Owned Personally Enabled (COPE) device users. Consumers of either group are driving and adopting technology at a faster rate than the enterprises which is termed as Consumerization of IT. This trend presents both challenges and opportunities for enterprises. A reasonable usage policy by the implementation of Mobile Device Management (MDM) solution helps the enterprises to avail most of the opportunities such as optimizing support cost, reducing business risks and administering corporate policies and procedures at ease and to avoid the potential pitfalls of proprietary information leakage & loss, network security threat and more. On the other hand, below is the list of do’s and don’ts that will help the employees to enjoy the benefits of safe use of personally owned and personally enabled devices at work.

Download Apps from Known Source: Refrain from downloading apps from unknown sources rather than procuring them from official websites.

Review the Apps: Even before downloading the apps from the official websites, read the reviews to know the general opinion of the apps.

Permissions: Be vigilant while granting permissions to install apps in your mobile devices

Safe Browsing Habits: Adopt a keen watch over the web surfing activities. The dangers that exist on the web can also exploit the mobile devices.

Phishing SMS or VM: Do not respond to questionable voicemail or text unless you call the institution directly and verify the information.

Password Authentication: Use standard password protection methods such as PIN numbers and automatically generated pass codes to enhance the physical security of the mobile device.  Enhance device security that minimizes the threat of losing personal information such as stored logins to banking and social media sites.

VPN Access: Use SSL VPN access to secure the session while accessing the corporate network resources using smartphones.

WiFi Hotspot Security: Almost all the modern devices are equipped with WiFi functionality. Avoid accessing the password protected websites such as banking or social media sites while connected to insecure WiFi hotspots when in a tea shop or in an airport terminal.

Remote Wipe & Encryption: Enable encryption, remote wipe facilities on mobile devices to protect data in the event a device is lost or stolen. 

Use Security Apps: Consider to buy robust security apps available in the market for mobile devices.

Update: Always keep the mobile device operating systems and software up-to-date.
To conclude, the employees in an enterprise gain the power of personal computers, when they use these hand-held devices such as the Smartphones and Tablets for their day-to-day tasks, but smarter and secured usage will help them to keep their personal and corporate data from out of the reach to other third party or external attacks.

By-Emma Watson

Tuesday, October 9, 2012

Enterprise Mobile Device Management

ZSL has designed MobilePower Center, a cross-platform Unified Mobile Device Management Solution that renders an intelligent mobile management solution to address the real time challenges of the organizations in leveraging mobility devices for their businesses ─ distribution and deployment of apps in user mobile devices; back-ups and disaster recovery management for business continuity, security & compliance management; scalability & high performance efficiency; lost device management and optimized resource utilization -- all at competitive pricing.


Is Security a Blow to BYOD?



In the recent times, smartphones and tablets are conquering the enterprises in breakneck speed. The concept of Bring Your Own Device (BYOD) is a growing trend in enterprise businesses. With the consumerization of enterprise mobility, a growing percentage of employees are bringing their personal devices to work. The relative shift from stable mobile environments to diverse mobile devices pose severe challenges to IT in different areas such as the access control, enforcement of corporate policies and procedures, security of confidential data on user devices and a number of mobile security issues. Security in BYOD seems to be serious threat to enterprises, which they can mitigate by devising and implementing appropriate security best practices through a successful personal BYOD program to run their business operations diligently.
As modern technological advancements like mobility penetrates deep into today’s corporate environments, the enterprise enjoy many benefits such as the increased employee productivity, satisfaction and effectiveness. However, there are significant concerns about the privacy and security of sensitive corporate data stored on these mobile devices that IT must tackle. Enterprises must adopt security best practices as a reasonable usage policy rather than viewing it as a deterrent to the BYOD program. The important security best practices an enterprise should employ for a safe BYOD program are discussed in this article.

Physical Security

Enterprises should enhance the physical security of the mobile devices accessing the corporate networks, through BYOD programs, by employing multifactor authentication. The existing corporate security policies must also be extended to BYOD such as enforcing the use of a user name, strong password with a combination of special characters, numbers & alphabets and a series of PIN numbers such as 4 digits personal identification numbers and 6 digits codes which are generated automatically and expire in a short duration of time, e.g. 30 or 60 sec.

Identity & Access

Enterprises should set access levels and permissions for each user or user groups accessing their corporate network using BYOD or COPE (company owned personally enabled) devices. This is accomplished by setting up user profiles for each of the employees in an enterprise. Access permissions need to be set for each of the business critical applications, folder and for files that are saved, read, edited and emailed. Thus, authorized mobile device users will access the corporate network in a secured manner. Devising a proper Mobile Device Management (MDM) solution would help the enterprises to keep track of the mobile devices (either company owned or employee owned) connected to the corporate network. The user management console of the MDM solution would help the IT managers to manage the identity and access settings for each of the employees in an enterprise. Centralized MDM software can also help to update the access rights and roll out the updates to the operating system and applications installed on the mobile devices from one central console.
Enterprises should also ensure that their cellular network service providers have built in security across their network. These include two-factor authentication support, anti-malware, anti-spam software, public key infrastructure (PKI) authentication and fraud detection.

Content Security

Enterprises should ensure that proper security protocols are in place on the corporate network, so that BYOD users accessing the network through their encrypted device from a Public IP would gain access to only authorized resources. BYOD does not mean that any corporate data in the enterprise network is freely accessible. A good combination of intelligent software’s such as anti-malware, data encryption, content filtration, data loss prevention (DLP) and intrusion prevention software help to safeguard the corporate data from un-authorized access. If the device is lost or stolen and falls into the hands of strangers, the enterprises must prevent the corporate data loss by remotely administering account lock-out or wiping features of the MDM software. Thus, content security is enforced with reasonable BYOD program in enterprises.

 

Remote Access with SSL VPN

Enterprises must setup a secure network connection for their BYOD users using virtual private networks (VPNs). Single socket layer virtual private network (SSL VPN) unlike the other VPNs renders employees with enormous flexibility to access the network securely from any remote location and from any mobile device. SSL VPNs provide access to shared resources without any security concerns in transmitting sensitive data over the internet, since it encrypts the data as it traverses over the internet. Furthermore, SSL VPN provides secure remote connectivity without the need for software to be installed on each device.

Detect Jail Breaks

Enterprises should automatically detect jailbroken or rooted mobile devices connecting to the corporate network in the BYOD program. Such devices need to be refused connectivity to the corporate networks and thus containing the resulting business risk. Enterprises should proactively assess the integrity of the mobile devices used for business during device enrollment and thereafter periodically. One way to accomplish this is by employing a MDM Solution in the corporate network that can detect the jailbroken or rooted devices. Push notifications need to be sent to the jailbroken devices to remedy the device, if it fails the compromised device need to be unenrolled from network or remotely wiped using MDM tools.

MDM & ITSM

Business IT teams look for MDM Solutions with the rising popularity of BYOD in enterprises. However, there exist a disconnection between MDM and ITSM (IT Service Management) strategies which results in inefficiencies and misunderstandings. Enterprises should efficiently integrate MDM capabilities to their existing ITSM platforms to gain control over all the assets such as desktops, laptops and mobile devices from a single focal point. This results in increased consistency and transparency throughout the organization. Profoundly, integrated solutions allow for complete control of devices, including enforcement of passcodes, detect jailbreaks or rooting, ability to remotely lock or wipe the lost or stolen devices and the ability to remotely configure WiFi or email configurations.

Conclusion

There are very many MDM products available in the market suiting to the specific needs of the enterprise and its security. The complex legal impact of the BYOD practice should be carefully considered by employing a multi-factor approach. Security in a BYOD program results in a reasonable personal device usage policy which mitigates the risks and it is truly a win/win game for the users and the organizations.

by Emma Watson

Monday, September 10, 2012

15 Best Security Practices for Mobile Device Management


Enterprises tend to enhance employee productivity by allowing smartphones and tablets at work. But, lack of essential security and mobile device management (MDM) strategies introduces new risks to the corporate resources and privacy of smartphone/tablet users. Security complexity will further increase, when enterprises adopt bring-your-own-devices (BYOD) to work. The data contained in these employee-owned personal devices are sensitive and critical to the enterprise businesses. Issues of security, compliance, legality, trust, device ownership, data leakage needs attention. Thus, a strong corporate policy coupled with the best security practices is essential for a good enterprise mobility initiative.
According to a recent Forrester Research Report, smartphones’ use by the US-based information workers is expected to triple by 2013. Also, the use of tablets to work is rising at a steep rate. Today within the US and Canadian businesses half of the smartphones are not company-issued equipment, reports Forrester. Most analysts feel that a better mobile device security strategy is to be made sooner than later. Let’s discuss here the top 15 best security practices for mobile device management that helps the enterprises to manage mobility and BYOD strategies in their business operations.

1 –Choice of Mobile Devices for Enterprises
The first and foremost strategy is the choice of the mobile devices. Mobile devices having inbuilt security is best to be used in the enterprises than the others that does not provide enough security which is commonly used by the general consumers. Enterprises need to allow only the mobile devices that have the best possible control and security inbuilt with them.

2 – Enterprises to Devise a Strong Security Policy
As most modern devices such as the smartphones and tablets do not have encryption inbuilt within the hardware, it is impractical to fully encrypt the mobile devices. However, enterprises must strive to employ a good encryption method which is a key to build a strong security policy by suitably choosing OS and device encryption methods. Device encryption method would help to encrypt the local storage, but enterprises must ensure that it covers all the risk areas including the internal and external memory. Enterprises should also adopt OS encryption methods by installing respective third-party apps to secure text messages, e-mails, calendars, contacts, voice calls and other critical communications. Thus, enterprises can suitably devise a strong security policy with the help of device and OS encryption methods.

3 –Extend Existing Corporate Security Policies to Mobile Devices
Enterprises should enforce the existing security policies, in practice, such as password protection, authentication access etc to the mobile devices also. That is, mobile devices accessing the corporate networks should be enforced to comply with the enterprises’ authentication and security process. Currently existing rules within the corporate networks such as passwords of specific maximum length with a combination of uppercase characters and special characters can be applied to mobile devices accessing the corporate networks.

4 –Effective Mobile Device Management Solution for Corporate Compliance
Enterprises that adopt Mobility and BYOD at work for its employees should have an effective Mobile Device Management solution in place in the absence of which mobile security becomes an optional and increases the security risks. An effective MDM solution to enforce organization’s compliance, policies and procedures will enable the enterprises to secure their corporate networks accessed over the mobility devices, to regulate the usage of mobile apps & devices and to manage their mobile application users.

5 – Registry of Mobile Devices
Take stock of the mobile devices connected to the corporate network. It is an important security principle to be employed in the corporate houses where mobility is enabled into their businesses. If an enterprise is specific about the type of smartphones/tablets it allows for its business operations, then security policies should be formulated to restrict the usage of the other type of devices. However, enterprises at its discretion can allow a new type of mobile device to connect to their corporate network but have them enrolled into your corporate compliance regulations and security policies to ensure security of your business data.

6 –Automated Wiping & Remote Locks
Identifying unusual situations like jail breaks, lost device, device theft, number of repeated failed login attempts or not connected to the network for lengthy period say for more than a month, and enabling those mobile devices for remote wiping, automatic padlocking and account locks is an essential security mechanism that enterprises need to adopt to safeguard enterprise data.

7 –Installing Only White-listed Applications
Enterprises of all sizes struggle to protect their network end points from constant attack of malware. Application white listing is one of the best practices that enterprises should try to implement to enhance the security of the mobile devices in their corporate network. This approach has gained traction during the recent days which works in reverse to the traditional defenses such as anti-virus and firewalls by permitting only good known files. Tentative listing of applications allows only authorized software to be installed on the mobile devices and prevents the malicious software from entering the corporate network. Also, it typically acts as a barrier to protect the mobile devices from being exploited with malicious software contents. This could be troublesome from the user perspective, but for the enterprises it is really a great step towards securing their corporate network.

8 – Common SSL VPN Connectivity
Enterprises should employ VPN access to enjoy the benefits of shared networks without any security concerns in transmitting sensitive data over the internet, since it encrypts the data as it traverses over the internet. Secure socket layer virtual private network (SSL VPN) can be used to share networks and secure remote access to users or group of users using laptops, PCs, smartphones and tablets to any other critical client–server resources used in the corporate network. This approach will reduce the overhead expenses of IT department by using a single tunnel for network access instead of one solution for laptops, PCs and another for tablets and mobile devices. So networks admin need to evaluate and select the appropriate SSL VPN gateway solution that supports all type of clients including PCs, laptops, tablets and mobile devices of all platforms.

9 –Reverse Web Proxies for Secured Access
Reverse web proxies performs authentication and encryption of the data access that is happening over the Web. This will enable its users access the Web in a secured manner from any of their client devices whether it is a smartphone or tablet or a laptop or PC. Reverse proxies can be created as an additional security layer to front-end public, private and trusted servers, while storing the sensitive and critical information in the internal network immune to the external security vulnerabilities and network attacks. Enterprises enabling mobility and BYOD into their businesses should implement these reverse proxies to provide safe access to its corporate networks for the users who are accessing to over the web from their smartphone or tablet devices.
10 – Run Regular Security Updates & Patches 
Any mobile operating systems and their upgrades and updates are prone to security vulnerabilities and hacker attacks, which is countered by parallel security patch releases. Enterprises need to ensure that the mobile devices connected to their corporate network are installed with regular security updates along with updates of new upgrades and patches for the mobile operating systems (iOS, Android OS, Blackberry OS, etc).      

11 –Extending Firewall Policies to Mobility Devices
Enterprises should control the traffic that is coming from the smartphones and tablets by setting up unique firewall policies. A firewall helps by restricting access to a corporate network and provides access that is really needed for the specific user. An example would be, setting off the access to a financial database with firewall and providing access to the network resources that users reasonably want to use.

12 – Installing Intrusion Prevention System
Enterprises need to install intrusion prevention systems (IPS) that is very essential to study the traffic that is coming from the smartphones and tablets. IPS helps to proactively respond to security threats initiated on the corporate network by the smartphones and tablets. They help to filter out the routine events from critical threats and also highlight the incidents that require immediate action. It is easy to visualize the attacks that are coming in from the smartphones and tablets as they being sophisticated devices.

13 –Securing Wireless (Wi-Fi) Connectivity
CNET News reports estimates that 90 per cent of the smartphones and tablet devices in usage will have Wi-Fi functionality by 2014. Enterprises must confirm the security of the wireless connectivity by devising various security measures such as disabling auto-connectivity to Wi-Fi. Security of the wireless network should also be enhanced on par with the wired networks by running deep packet inspection. Traffic connected to the corporate network through Wi-Fi devices should apply WPA2 and deep packet inspection. Proper intrusion prevention software should be in place for mobile devices connected through Wi-Fi devices.

14 –Secured Bluetooth Usage
Though Bluetooth is a very advantageous feature for smartphone users where they can talk hands free while they drive or perform another task, they are easily prone to hacker attacks. The discoverable feature of blue tooth makes the devices vulnerable to hackers. Enterprises must enforce to disable or toggle the Blue-tooth devices to hidden mode that are not in active information transmission. Blue-tooth functionality in today’s smartphones helps the users to talk easily with hands-free headsets, but is easily prone to hackers. This is also a way hacker’s gain access to the devices because of the always-on and always discoverable feature of the Blue-tooth device.

15 – Follow Federal & State Laws
 The US states and other Governments have stringent local laws governing the exposure of sensitive and private data of their residents. It is high time enterprises need to be aware of those laws and include them in their corporate security policies governing the usage of smartphones and tablets into their businesses. It would be mandatory for the enterprises to encrypt all the customer data on the mobile devices to comply with the federal and state notification laws.

Friday, July 6, 2012

Everything about Mobile Apps that you want to know!

What are Mobile Apps?
Mobile Apps are applications or services that can be downloaded and installed to a mobile device, rather than being rendered within a browser, which helps to meet personal use or business requirements for the user. The app may pull content and data from the Internet, in similar fashion to a website, or it may download the content so that it can be accessed without an Internet connection. A mobile app may be a mobile Website bookmarking utility, a mobile-based instant messaging client, Gmail for mobile, and many other applications.
The small-business demographic is pushing the envelope when it comes to mobile technology adoption. The fact is that they have really being doing so for the last decade.
The Corporate Mobile App Strategy Survey, published by partnerpedia.com, found that 78 per cent of the large companies with 500 employees or more had a desire to purchase apps. Of those, 90.2 per cent intend to buy mobile solutions for use by employees, while 43.9 per cent wanted apps for customers. The survey, which also included responses from companies with less than 500 employees, found that 22 per cent are buying apps for contractors.
And, close to 40 percent of small-business owners are using five more mobile apps to run their business, according to an ongoing survey conducted by J2 Global.
The number of mobile business apps – some cloud-based, some residing on the device – is proliferating. We can expect to see even more being developed as a result of the new HTML 5 standard, says David Bradshaw, a research manager at analyst IDC. HTML 5 makes it possible to develop apps simultaneously for different mobile platforms, so that a business that chooses to roll out a sales app. There are also a growing number of apps designed specifically for mobile use. These can be very generic or targeted at particular sectors.
Business Advantages of Mobile Apps:
If personal mobile phones and tablets are now an integral part of working life, how can enterprises turn this to business advantage? Many organisations have started carefully, by allowing employees to access the firm’s email and calendar applications from their mobile devices. Even this can save time and money.
The advantage of an enterprise app store is that the IT function can configure apps appropriately before they are downloaded, and create blacklists or whitelists of apps for users. IT then has a single point from which to manage the provisioning and decommissioning of apps and the implementation of security policies.
However, most of the companies allow users to choose their own mobile apps, because users understand their own needs better than the IT function. Whichever approach is chosen, it is still hugely important to put security policies in place to protect corporate data.
Mobile Apps are popular with business owners and their customers. With today's market going mobile, Apps help you keep pace:
Benefits for Business – Apps:
  • Build relationships
  • Build loyalty
  • Reinforce your brand
  • Increase your visibility
  • Increase your accessibility
  • Solve the problem of getting stuck in spam folders
  • Increase sell-through
  • Increase exposure across mobile devices
  • Connect you with on-the-go consumers
  • Generate repeat business
  • Give you tools that are driving the "New App Economy"
  • Enhance your social networking strategies
Symantec's 2012 State of Mobility survey has revealed an uptake of mobile applications within enterprises across the globe.
Commissioned by Symantec, Applied Research spoke with 6,275 organisations in 43 countries from August to November in 2011.
The survey highlighted an expansion of both adapting and customising mobile software for business purposes across the board -- 71 percent of enterprises stating that there were at least current discussions concerning the ways in which custom mobile applications could assist their business, including the idea of custom 'stores' for employees to download authorised and corporation-related applications.
In terms of an improvement in business practices and increased efficiency levels, according to the survey, 73 percent of small and large corporations alike have enjoyed a positive result through the adoption of mobile technology.
What’s New in Mobiles apps market?
As the smartphone market grows, so too do the apps you can use on them, uses of mobile app technology to get you up to speed with your handheld device and its potential.
Following are the trending Mobile Apps top opportunities that are already taking hold of the mobile app market or that we expect to take off in the near future.
Mobile Health
In the recent days Mobile apps are changing the way healthcare industry do business, permeating every step of the health and core aspect of their operations.
Nine percent of all cell owners have apps on their phones that help them track or manage their health.
"I was surprised to see that almost one in ten cell phone users have a health app. I thought it would be lower,” said Susannah Fox, Associate Director of Pew Research Center's Internet & American Life Project and author of the report, 85 percent of American adults who use a mobile phone today 17 percent have used their phone to look up health or medical information. The percentage goes up to 15 percent for mobile phone users aged 18 to 29-years-old. Only 8 percent of mobile phone users aged 30 to 49-years-old and 11percent of aged people use health apps.
Urban cell phone owners are also more likely than those who live in suburban or rural areas to have a mobile health app on their phone.
Many consumers also have health-related apps on their smartphones to get nutrition information, count calories, calculate body mass index and learn new exercises, the survey found.


Localized Deal Updates
The explosion of location-based technology was revolutionary in the app world. Now we’re using that location information to deliver personalized and relevant updates and alerts. The number of apps and services that support hyper-local experiences is on the small side, but this is an area that is ripe for growth.
Location-based services like Loopt, Foursquare and Gowalla are all investigating ways to let users know not just when their friends are nearby, but what offers are available in their areas.
Mobile Travel
Mobile technology has revolutionized the travel industry: Countless travel apps have popped up, promising to enhance your experience in foreign lands. There are lots of useful travel mobile apps helps users to book the flights and also allows passengers to virtually "check in" into airports using foursquare. Customers may also share their experiences through other social networks.
Half of the airlines have already implemented mobile services for flight search and check-in with close to half also providing boarding passes, ticket purchase and flight status notifications.
The latest Airline IT Trends Survey reveals that a whopping 93% of airlines have mobile services for passengers as a top investment priority over the next three years, with 58% investing in major programmes. It predicts that information technology and communications (IT&T) spend as a proportion of revenue is expected to stay stable, at around 1.65% in 2012.
While only half the respondents, made up of more than 50% of the world's top 100 airlines, expect IT spend in 2013 to increase in absolute terms.

Social Media
Mobile social networking is social networking where individuals with similar interests converse and connect with one another through their mobile phone and/or tablet. Mobile Social Apps that can connect you to twitter, Facebook, Google Plus, LinkedIn, Flickr together where you can post status updates, share photos, videos, likes, retweets. For instance, the photo sharing apps that support the widest range of share targets tend to be more popular. Even apps like Path — which by design are meant to be private — have learned that it is essential to allow users to post their data to other networks, like Facebook.
Mobile Commerce
The world is increasingly becoming mobile. The technology creators of today are creating goods for the mobile consumer. The concept of social commerce can be taken literally, as in making a purchase directly through a social media property. Far more important is the degree to which content shared through social media is influencing purchasing decisions, which is happening on a massive scale. 33 million consumers shop with a mobile phone according to research firm Experian Simmons. 24% of U.S. adult online iPhone users and 21% of Android users have used a shopping application in the past three months. (Source: Forrester, 2011)
The ways of communicating with your customers is changing and businesses need to adapt to these changes in order to stay ahead of their competitors.