Mobile security can’t ignore device, say panelists
From: FierceGovernmentIT
By David Perera
Federal efforts to secure increasingly ubiquitous mobile devices will concentrate more and more on security at the data layer–but device security can’t be forgotten, said panelists during a June 20 panel sponsored by AFECA Bethesda.
“Focusing on the information is definitely where we’re going to put more of our effort–but protecting information is even harder than protecting systems,” said Sean Donelan, network and infrastructure program manager within the Homeland Security Department’s national cyber security division.
A federal mobile security reference architecture under development by DHS is undergoing review, with the cyber security division planning to release a draft version this summer, Donelan added.
Still, good security can’t ignore the entire mobile stack, including device hardware and firmware, said Ron Ross, a senior computer scientist and information security researcher at the National Institute of Standards and Technology.
“You can’t divorce yourself from the actual device itself, because that’s where the controls are deployed,” he said after the panel discussion.
Rick Holgate, chief information officer of the Bureau of Alcohol, Tobacco, Firearms and Explosives, echoed Ross. “At some level you can’t say it’s only about the data. It’s also about–whether you call it the device or the operating system,” he said.
Asked if the need to create device-specific security profiles might cause federal agencies to centralize on a platform of choice–and so not be platform agnostic, as many say they want to be–Holgate said “it could.”
Containerization as a security strategy is fairly device agnostic, Holgate said, but it has the drawback of turning off functionality that makes smart mobile devices so attractive in the first place.
| Print article |