{"id":826,"date":"2009-11-28T16:42:37","date_gmt":"2009-11-28T11:12:37","guid":{"rendered":"https:\/\/www.qadit.com\/blog\/?p=826"},"modified":"2009-12-01T07:33:54","modified_gmt":"2009-12-01T02:03:54","slug":"checklist-to-secure-data-in-mobile-phones","status":"publish","type":"post","link":"https:\/\/qadit.com\/blog\/checklist-to-secure-data-in-mobile-phones\/","title":{"rendered":"Checklist to secure data in mobile phones"},"content":{"rendered":"<p style=\"text-align: justify\">As per a recent statistic, about a million mobile handsets are getting lost every year.  While mobile phones carry valuable data such as business contacts, emails, documents, pictures, videos, etc. and senior management executives are increasingly using their smart phones compared to laptops, securing mobile phones is not given top priority in the IT security agenda of many business organizations. It is highly recommended that every organization includes a \u2018Mobile Phone Security Policy\u2019 in their IT Security Policy and Procedures. The policy may include a security checklist similar to the one given below.<!--more--><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">\n<p style=\"text-align: justify\"><strong>1.\tPhysical Security<\/strong><\/p>\n<p style=\"text-align: justify\">a.\tMobile phones should never be left unattended.<\/p>\n<p style=\"text-align: justify\">b.\tLending the phone to another person should be avoided.<\/p>\n<p style=\"text-align: justify\">c.\tEnable \u2018Lock Mobile\u2019 on removal of SIM card if such feature is available in the mobile.<\/p>\n<p style=\"text-align: justify\">d.\tEnable \u2018Mobile Tracker\u2019, if this feature is available in your mobile. By configuring this feature, whenever the SIM is replaced by another SIM, a distress SMS will be sent to a set of user pre-configured mobile numbers without any indication on the compromised mobile. Once distress SMS is received, the mobile can be located with the help of the telecom service provider \/ police. Some mobile tracker software also aids \u2018remote wipe\u2019 of data.<\/p>\n<p style=\"text-align: justify\">e.\tSome mobile security solutions like the one from Kaspersky have features like remote lock, remote data wipe etc. Users may consider these solutions to be implemented in their handsets.<\/p>\n<p style=\"text-align: justify\">f.\tDatabase of IMEI (International Mobile Equipment Identity) numbers of all mobiles in the organization with their respective user names should be maintained by the IT department. This will be required in case of reporting loss to the police authorities or the service providers.<\/p>\n<p style=\"text-align: justify\">\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\"><strong>2.\tUser Authentication<\/strong><\/p>\n<p style=\"text-align: justify\">a.\tProtect your mobile using passwords and PINs<\/p>\n<p style=\"text-align: justify\">b.\tEnable and configure the automatic timeout feature in your mobile phone. This feature locks the handset after reaching a present inactivity time threshold.<\/p>\n<p style=\"text-align: justify\">\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\"><strong>3.\tData Backup<\/strong><\/p>\n<p style=\"text-align: justify\">Data can be backed up in the following 3 ways:<\/p>\n<p style=\"text-align: justify\">a.\tCopying the data onto the memory card. But this only protects the user from data loss due to a hardware failure.<\/p>\n<p style=\"text-align: justify\">b.\tSynchronizing the data with a desktop. Most mobiles come with a backup \/ synchronization utility to facilitate this.<\/p>\n<p style=\"text-align: justify\">c.\tBacking up service provided by the Telecom Service Provider.<\/p>\n<p style=\"text-align: justify\">\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\"><strong>4.\tData Encryption<\/strong><\/p>\n<p style=\"text-align: justify\">Most smart phones come with encryption facilities. Encryption of both device contents and memory card contents should be considered.<\/p>\n<p style=\"text-align: justify\">\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\"><strong>5.\tAvoid unknown contacts and suspicious websites<\/strong><\/p>\n<p style=\"text-align: justify\">a.\tAvoid message \/ file downloads from unknown contacts.<\/p>\n<p style=\"text-align: justify\">b.\tAvoid file downloads from suspicious websites.<\/p>\n<p style=\"text-align: justify\">c.\tAvoid installing unwanted and suspicious applications.<\/p>\n<p style=\"text-align: justify\">d.\tIncoming bluetooth connections should not be accepted unless from known sources.<\/p>\n<p style=\"text-align: justify\">\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\"><strong>6.\tTurn off wireless interfaces when not used<\/strong><\/p>\n<p style=\"text-align: justify\">a.\tWireless interfaces such as Bluetooth, Wi-fi and infrared should be turned off if not in use.<\/p>\n<p style=\"text-align: justify\">b.\tAutomatic connections to data services such as GPRS and EDGE should be turned off when not in use to avoid malware infection and spreading of malware by infected handset automatically.<\/p>\n<p style=\"text-align: justify\">c.\tAdjust bluetooth connectivity power setting to lowest levels to prevent long range attack.<\/p>\n<p style=\"text-align: justify\">\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\"><strong>7.\tPrevention and detection software<\/strong><\/p>\n<p style=\"text-align: justify\">Prevention and detection software to defend against malware and other forms of attack is an important step in securing the mobiles. Most mobile devices come with these kind of security features. If not, users may evaluate third party products. Organizations may consider implementing centralized security management to have a single, unified and centralized control over all the mobile devices used within the organization. The security software should have the following functionalities:<\/p>\n<p style=\"text-align: justify\">a.\tFirewall<\/p>\n<p style=\"text-align: justify\">b.\tAntivirus<\/p>\n<p style=\"text-align: justify\">c.\tIntrusion Detection<\/p>\n<p style=\"text-align: justify\">d.\tAnti-spam<\/p>\n<p style=\"text-align: justify\">e.\tVPN<\/p>\n<p style=\"text-align: justify\">f.\tGroup Security Policy<\/p>\n<p style=\"text-align: justify\">g.\tRemote locking<\/p>\n<p style=\"text-align: justify\">h.\tRemote diagnostics<\/p>\n<p style=\"text-align: justify\">\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\"><strong>8.\tPatch Management<\/strong><\/p>\n<p style=\"text-align: justify\">Mobile manufacturers come out with new patches and upgrades to fix security holes in the existing operating system of the handheld device. Users should update their OS at periodic levels by checking the manufacturer\u2019s website.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>As per a recent statistic, about a million mobile handsets are getting lost every year. While mobile phones carry valuable data such as business contacts, emails, documents, pictures, videos, etc. and senior management executives are increasingly using their smart phones compared to laptops, securing mobile phones is not given top priority in the IT security &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/qadit.com\/blog\/checklist-to-secure-data-in-mobile-phones\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Checklist to secure data in mobile phones&#8221;<\/span><\/a><\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","enabled":false},"version":2}},"categories":[12,13],"tags":[51,114,113],"class_list":["post-826","post","type-post","status-publish","format-standard","hentry","category-itsec","category-network","tag-information-security","tag-mobile-phone","tag-mobile-security"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p9AH7Q-dk","_links":{"self":[{"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/posts\/826","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/comments?post=826"}],"version-history":[{"count":0,"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/posts\/826\/revisions"}],"wp:attachment":[{"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/media?parent=826"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/categories?post=826"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/tags?post=826"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}