From: FierceGovernmentIT

By David Perera

Federal efforts to secure increasingly ubiquitous mobile devices will  concentrate more and more on security at the data layer–but device security  can’t be forgotten, said panelists during a June 20 panel sponsored by AFECA  Bethesda.

“Focusing on the information is definitely where we’re going to put more of  our effort–but protecting information is even harder than protecting systems,”  said Sean Donelan, network and infrastructure program manager within the  Homeland Security Department’s national cyber security division.

A federal mobile security reference architecture under development by DHS is  undergoing review, with the cyber security division planning to release a draft  version this summer, Donelan added.

Still, good security can’t ignore the entire mobile stack, including device  hardware and firmware, said Ron Ross, a senior computer scientist and  information security researcher at the National Institute of Standards and  Technology.

“You can’t divorce yourself from the actual device itself, because that’s  where the controls are deployed,” he said after the panel discussion.

Rick Holgate, chief information officer of the Bureau of Alcohol, Tobacco,  Firearms and Explosives, echoed Ross. “At some level you can’t say it’s only  about the data. It’s also about–whether you call it the device or the operating  system,” he said.

Asked if the need to create device-specific security profiles might cause  federal agencies to centralize on a platform of choice–and so not be platform  agnostic, as many say they want to be–Holgate said “it could.”

Containerization as a security strategy is fairly device agnostic, Holgate  said, but it has the drawback of turning off functionality that makes smart  mobile devices so attractive in the first place.