December 17, 2010

Safe use of Smartphones

The increasingly intensive use of smartphones in our day to day, led the European Network and Information Security Agency (ENISA) to study the risks of their use and make several recommendations on data security in these devices.
 
The main risks include spyware, weak data cleaning when the phones are recycled, accidental data loss and unauthorized telephone calls and SMS value-added.

The most important results of the report are the list of risks and recommending, a comprehensive set of strategies for maintaining the smartphone safer.
 
In summary, the recommendations are:

RECOMMENDATIONS


General Consumers:
  • Automatic lock: set up your smartphone so that it locks automatically after a few minutes.
  • Check the reputation: before installing or using the new smartphone applications and services, check their reputation. Never install any software for the device unless it is from a trusted source or that has been requested by you.
  • Check permission requests: review requests for permission to install of applications or services on the smartphone.
  • Reset and clear: Before disposing of or recycling their phones, wipe all data and settings.
Employees:
  • Decommissioning: before being transferred to another user or recycled, carefully review all the data you have in your phone and delete them permanently.
  •  Installing App: If sensitive corporate data are handled on the phone, or if the corporate network is available to your smartphone, you should define the list of approved applications (whitelist app) that can access company data.
  • Confidentiality: use data encryption for data on your smartphone memory and removable devices.
Senior officials:
  • No local data: do not store sensitive data locally and only allow online access to confidential data from a smartphone that does not keep data in cache.
  • Cryptographic software: to use highly confidential, use encryption software for SMS and calls.
  • Periodic Reload: smartphones should be periodically cleaned (using secure deletion) and reloaded with a disk image, specially prepared and tested.
This is a summary of a report from  ENISA. To read the full report click here.

No comments:

Post a Comment