Cyber attacks target ISIS in a new line of comba... » Security experts react to The New York Times article, “US Cyberattacks Target ISIS in New Line of Co... FAST and V.i. Labs join forces to educate market... » The Federation Against Software Theft (FAST) and long-term industry member V.i. Labs, have launched ... Wick Hill Wins ‘Distributor of the Year’ at IT E... » Woking, Surrey: Wick Hill has won the strongly contested ‘Distributor of the Year’ title at the IT E... Thales delivers digital trust across connected ... » Samsung Developer Conference, San Francisco, CA: Thales has announced that the SAMSUNG ARTIK™ platfo... BeyondTrust contributes threat analytics to the ... » PHOENIX: BeyondTrust has announced today that the 2016 Verizon Data Breach Investigations Report (DB... Construction hoist standard for transporting ... » BSI, the business standards company has revised BS 7212:2016 Code of practice for the safe use of co... FireMon delivers record 2015 Revenue...adds secu... » London, UK: FireMon CEO Jim Lewandowski has announced the security management firm achieved record g... PALFINGER achieves new record levels of revenue » - Revenue grew by 9.1 per cent to EUR 318.8 million - EBIT showed extraordinarily strong increase o... Industry leader covers nearly 700 compliance pol... » London, UK: Tripwire, Inc. has announced that Tripwire® Enterprise coverage for security policy and ... Varonis to stifle ransomware with new threat model... » London, UK: Varonis Systems, Inc. has announced the beta availability of more than 20 new threat mod...

CLICK HERE TO

Advertise with Vigilance

Got News?

Got news for Vigilance?

Have you got news/articles for us? We welcome news stories and articles from security experts, intelligence analysts, industry players, security correspondents in the main stream media and our numerous readers across the globe.

READ MORE

Subscribe to Vigilance Weekly

Information Security Header

Acceptance of “Bring Your Own Device” means companies must get to grips with Cloud and Application Security

London: Company policies supporting Bring Your Own Device are being widely embraced as a win-win initiative that improves employees’ experience and reduces IT costs, according to results released today of the (ISC)2® 2013 Global Information Security Workforce Study, conducted on behalf of the (ISC)2 Foundation by the analyst firm Frost & Sullivan. At the same time, information security managers admit that companies must do more to understand the security of the technologies behind the trend, particularly for cloud-based systems and applications.

A preview of select results of the (ISC)2 (“ISC-squared”) study were featured at a press conference hosted by Reed Events in advance of Information Security Europe 2013, April 23 -25. The largest study of its kind examining workforce trends in information security covered BYOD as one of three game-changing technology trends that are having a significant impact on information security practice. The global study’s 12,396 respondents, one in four of which work in the EMEA region, clearly establish that BYOD is a prevalent practice - with 53 percent saying their companies actively allow users, either employees, business partners or both, to connect their devices onto their networks. A similar percentage, 54 percent, identified BYOD as a growth area for training and education within the information security profession.

Security professionals, however, are concerned that companies are not prepared for the risks introduced by this trend. Seventy-eight percent consider BYOD to present a somewhat or very significant risk. This reflects increased levels of concern compared to the 2011 study, when mobile devices were identified as a significant risk by 68 percent of respondents.

Further, nearly three-quarters of respondents (74 percent) highlighted that new security skills are going to be required to manage the security risks associated with BYOD. The biggest concerns were over the state of application security (72 percent) and the cloud (70 percent), also a developing area in business systems. Another 66 percent suggested companies needed to get more of a grip on how compliance requirements are being affected with the prevalence of BYOD.

Companies are more open to allowing user-owned smartphones (87 percent) and tablets (79 percent) onto corporate networks than laptops (72 percent), while they are supporting a multitude of platforms, with iOS leading the pack (84 percent), closely followed by Android (75 percent); RIM Blackberry/QNS (62 percent), and Windows Mobile (51 percent).

“Whether approved or not, user-owned tablets and smartphones are connecting into corporate networks and cloud environments,” states Michael Suby, Stratecast VP of Research at Frost & Sullivan. “Furthermore, the escalating capabilities of these devices, such as dual-core processors and multi-gigabytes of storage, add to the level of risk these devices pose to corporate assets and sensitive information. The positive news is that information security professionals are using a growing array of security technologies to stem this risk.”

The business drivers given for turning to BYOD puts the user at the centre of IT strategy. The desire to improve end-user experience at 60 percent was almost equal to the business requirement of supporting a mobile workforce (64 percent). A significant number of respondents (44 percent) also noted the goal of reducing operating and end-user support costs; while the desire to lower IT inventory costs was noted by a much lower 21 percent.

“From a security perspective, BYOD is gaining attention, but current efforts are focussed on the end –point rather than on protecting business data and assets,” says Wim Remes, CISSP, member of the (ISC)2 Board of Directors.

The top technologies identified to mitigate risks include: encryption, the use of virtual private networks, and remote lock and wipe functionality. Less than half (42 percent) are working with applications access control or authentication (40 percent), basic controls that exist on traditional IT infrastructures.

“This can be an opportunity for IT operations to fully seize the role of a business enabler. If approached correctly, with a focus on the data, BYOD can actually improve security and enable the business to compete at a pace that was but a remote dream half a decade ago,” concludes Remes, who presented the results at the conference.

The (ISC)2 Foundation will release the full report of the 2013 (ISC)2 Global Information Security Workforce Study in February as a resource to industry. Based on findings of an industry survey conducted in the autumn of 2012, the study is unique in its focus on issues affecting the security profession rather than general market developments, products or security breaches. Participants from 145 countries around the world contributed to offer insights into the changing profile of the profession, training and development needs, salary levels, attitudes and developments toward risk management, and the impact of key trends in business systems on security management