Home > Enterprise Desktop Tips > Windows desktop security tips > Windows mobile security: Get it locked down
Enterprise Desktop Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

WINDOWS DESKTOP SECURITY TIPS

Windows mobile security: Get it locked down


Kevin Beaver, CISSP
11.05.2008
Rating: --- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


I recently acquired a Windows mobile-based Samsung BlackJack smartphone. I absolutely love it but I feel it's quite the liability hanging off my pocket. I can't imagine being responsible for dozens, if not thousands, of these types of systems in larger enterprises. But this is the case for many people – people that are used to only having to secure Windows workstations and servers.

Mobile systems are a glaring weakness within enterprise security and not enough people are concerned about or have the right resources to address this. There's often no direct accountability in managing and securing mobile systems, and they often fall outside the scope of security assessments and audits. Interestingly, there's not a ton of vendor-based solutions to lock down these devices either. The ones that do exist focus on the older versions of PocketPC.

Lack of visibility and limited security solutions aside, the odds are that you have a whole lot of untamed Windows Mobile-based devices floating around your environment. The security risks associated with Windows Mobile systems are really no different than those commonly tied to laptop computers. They include:

The big difference is that you can't really test Windows Mobile systems using traditional security testing tools. It's just the nature of the beast.

These weaknesses not only expose sensitive files and email to whoever comes into contact with the mobile devices, but they also facilitate data leakage and sensitive information exposure by employees who aren't on the up and up. Windows mobile-based systems are that much more vulnerable because they have a greater propensity than the typical laptop to be lost and sprout legs, never to be seen again.

Ensuring that your Windows Mobile systems are properly locked down and are protecting sensitive business assets all starts with policies. I know policie


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Windows desktop security tips
How Windows 7 stands up to security tests
Securing sensitive data on Windows-based laptops
Gathering and documenting your Windows desktop security policies
Windows desktop security standards documentation best practices
Desktop security preparation for a new wave of Windows apps
Four Internet Explorer 8 group policy security settings
The state of enterprise security and emerging threats in 2009
Why should Windows shops use Microsoft Baseline Security Analyzer?
A first look at Windows 7 security enhancements
Using Sysinternals tools in security management scenarios

Windows Mobile device management
Mobile Device Manager joins Windows domains to mobile devices
Citrix aims to dazzle with self-service portal, iPhone client
Windows desktop endpoint security challenges podcast series
Windows Mobile security tips for the on-the-go pro
Security tools that can boost Windows mobile security
Remote user security checklist
Endpoint security quiz
Endpoint security
Step-by-step guide: Laptop hacking
Step 2: How to crack a laptop

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


s aren't sexy, but regardless of how boring and repetitive they seem, it's an absolute must to make sure your mobile systems fall within the scope of all your other computer systems.

Your mileage will vary but you should at least make sure the following Windows Mobile concerns are addressed in your existing security policies, standards and plans:

Beyond policies, here are the essential security must-haves for all Windows Mobile systems in your organization:

In addition to those lock-down practices, be sure to check out Microsoft's Security Model for Windows Mobile 5.0 and Windows Mobile 6 and Security Considerations for Windows Mobile Messaging in the Enterprise.

Locking down smartphones and PDAs is one of those darker places of security, and it's gone unexplored for too long. Whether these systems are business-owned or not, if employees are using them for business email, office applications and file storage, then those systems need to fall under your control. There's no time to drag your feet. Mobile device business risks are bound to rear their ugly heads if they haven't already. Address these issues now. As Windows Mobile usage becomes more widespread in the coming years, you'll appreciate the effort you put forth today for getting things under control.

About the author: Kevin Beaver is an independent information security consultant, keynote speaker and expert witness with Atlanta-based Principle Logic LLC where he specializes in performing independent security assessments. Kevin has authored/co-authored seven books on information security, including Hacking For Dummies and Hacking Wireless Networks For Dummies (Wiley). He's also the creator of the Security On Wheels information security audio books and blog providing security learning for IT professionals on the go. Kevin can be reached at kbeaver@principlelogic.com.


Rate this Tip
To rate tips, you must be a member of SearchEnterpriseDesktop.com.
Register now to start rating these tips. Log in if you are already a member.




DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Enterprise Desktop Security - Virus Protection, Malware Protection, Intrusion Detection
HomeTopicsITKnowledge ExchangeTipsMultimediaWhite PapersBlogs
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2008 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts