How to balance mobile privacy vs security

By 42Gears Team
byod-banner-blog
“BYOD strategies are the most radical change to the economics and the culture of client computing in business in decades”. -
  • ISO 27000 Series standards (known as ISMS Family of Standards) jointly published by ISO and IEC for information security1,
  • COBIT (Control Objectives for Information and Related Technology) created by ISACA for IT management and governance it allows manager to bridge the gap between control requirements, technical issues, and business risks2,
  • SOGP (Standard of Good Practice) published by Information Security Forum to provide a business-focused, practical and comprehensive guide to identifying and managing information security risks in organizations and their supply chains3,
  • ITIL (it is based on ISO 27001 standard)
Though there are universally accepted standards to secure data, using them on personal phones and devices invites employee restraint and push back. E.g. Location tracking technology is very helpful in case device is lost, data can be easily restored. However, people feel it’s an invasion to their privacy4
5:
  • Legal & liability aspects,
  • Impact of security and privacy controls on BYOD users,
  • Technical control measures,
  • Perception and behavior of users,
  • Information security standards and procedures,
  • BYOD awareness and training program.
Legal & Liability aspects
The impact of Security and Privacy controls on BYOD users
technical controls
Perception and view of employees
Information security standards and procedures
BYOD awareness and training program
6
  1. Data collection limit: There should be a limit to personal data collection. Data should be obtained in a legal manner with prior consent of the individual.
  2. Relevance of Information: Information should be accurate and relevant for the purposes it is being used.
  3. Purpose of obtaining information should be defined: Data should be used for the purpose it is defined for. Information should be deleted once it is used or no longer needed.
  4. Protection of Information: Security measures should be taken to protect personal information from getting lost, misused, disclosed and modified.
  5. Individual involvement: Every individual has a right to involve for the information taken from him. A person can ask for deleting information once used7.
  6. http://standards.iso.org/ittf/PubliclyAvailableStandards/
  7. https://en.wikipedia.org/wiki/COBIT
  8. https://en.wikipedia.org/wiki/Standard_of_Good_Practice
  9. http://searchmobilecomputing.techtarget.com/tip/How-to-balance-mobile-device-privacy-vs-security
  10. https://www.privacyinternational.org/node/44
  11. http://oecdprivacy.org/

“Written with expertise and passion to help you understand the topic better.”

4
42Gears Team – Content Author
Published on: June 8, 2016

Subscribe to our newsletter

Stay updated with the latest news, articles, and resources on enterprise mobility.

Weekly articles
Actionable insights delivered once a week. No noise.
No spam
Your privacy matters. Unsubscribe anytime.