
“BYOD strategies are the most radical change to the economics and the culture of client computing in business in decades”. -
- ISO 27000 Series standards (known as ISMS Family of Standards) jointly published by ISO and IEC for information security1,
- COBIT (Control Objectives for Information and Related Technology) created by ISACA for IT management and governance it allows manager to bridge the gap between control requirements, technical issues, and business risks2,
- SOGP (Standard of Good Practice) published by Information Security Forum to provide a business-focused, practical and comprehensive guide to identifying and managing information security risks in organizations and their supply chains3,
- ITIL (it is based on ISO 27001 standard)
5:
- Legal & liability aspects,
- Impact of security and privacy controls on BYOD users,
- Technical control measures,
- Perception and behavior of users,
- Information security standards and procedures,
- BYOD awareness and training program.
The impact of Security and Privacy controls on BYOD users
technical controls
Perception and view of employees
Information security standards and procedures
BYOD awareness and training program
6
- Data collection limit: There should be a limit to personal data collection. Data should be obtained in a legal manner with prior consent of the individual.
- Relevance of Information: Information should be accurate and relevant for the purposes it is being used.
- Purpose of obtaining information should be defined: Data should be used for the purpose it is defined for. Information should be deleted once it is used or no longer needed.
- Protection of Information: Security measures should be taken to protect personal information from getting lost, misused, disclosed and modified.
- Individual involvement: Every individual has a right to involve for the information taken from him. A person can ask for deleting information once used7.
- http://standards.iso.org/ittf/PubliclyAvailableStandards/
- https://en.wikipedia.org/wiki/COBIT
- https://en.wikipedia.org/wiki/Standard_of_Good_Practice
- http://searchmobilecomputing.techtarget.com/tip/How-to-balance-mobile-device-privacy-vs-security
- https://www.privacyinternational.org/node/44
- http://oecdprivacy.org/