You Got Chocolate On My iPad! Barry Caplin Chief Information Security Officer MN Department of Human...

42
You Got Chocolate On My iPad! Barry Caplin Chief Information Security Officer MN Department of Human Services MN Gov’t. IT Symposium Session 100: Thurs. Dec. 8, 2011 [email protected] [email protected], @bcaplin, +barry caplin (Toys in the Office)

Transcript of You Got Chocolate On My iPad! Barry Caplin Chief Information Security Officer MN Department of Human...

Page 1: You Got Chocolate On My iPad! Barry Caplin Chief Information Security Officer MN Department of Human Services MN Gov’t. IT Symposium Session 100: Thurs.

You Got Chocolate On My iPad!

Barry Caplin

Chief Information Security Officer

MN Department of Human Services

MN Gov’t. IT Symposium

Session 100: Thurs. Dec. 8, 2011

[email protected]

[email protected], @bcaplin, +barry caplin

(Toys in the Office)

Page 2: You Got Chocolate On My iPad! Barry Caplin Chief Information Security Officer MN Department of Human Services MN Gov’t. IT Symposium Session 100: Thurs.
Page 3: You Got Chocolate On My iPad! Barry Caplin Chief Information Security Officer MN Department of Human Services MN Gov’t. IT Symposium Session 100: Thurs.

http://about.me/barrycaplin

Page 4: You Got Chocolate On My iPad! Barry Caplin Chief Information Security Officer MN Department of Human Services MN Gov’t. IT Symposium Session 100: Thurs.
Page 5: You Got Chocolate On My iPad! Barry Caplin Chief Information Security Officer MN Department of Human Services MN Gov’t. IT Symposium Session 100: Thurs.
Page 6: You Got Chocolate On My iPad! Barry Caplin Chief Information Security Officer MN Department of Human Services MN Gov’t. IT Symposium Session 100: Thurs.

Apr. 3, 2010

300K ipads1M apps250K ebooks… day 1!

Page 7: You Got Chocolate On My iPad! Barry Caplin Chief Information Security Officer MN Department of Human Services MN Gov’t. IT Symposium Session 100: Thurs.
Page 8: You Got Chocolate On My iPad! Barry Caplin Chief Information Security Officer MN Department of Human Services MN Gov’t. IT Symposium Session 100: Thurs.
Page 9: You Got Chocolate On My iPad! Barry Caplin Chief Information Security Officer MN Department of Human Services MN Gov’t. IT Symposium Session 100: Thurs.

http://www.bbspot.com/News/2010/03/should-i-buy-

an-ipad.html

Page 10: You Got Chocolate On My iPad! Barry Caplin Chief Information Security Officer MN Department of Human Services MN Gov’t. IT Symposium Session 100: Thurs.
Page 11: You Got Chocolate On My iPad! Barry Caplin Chief Information Security Officer MN Department of Human Services MN Gov’t. IT Symposium Session 100: Thurs.

Don't Touch!

Pharmaceuticalcoating

Page 12: You Got Chocolate On My iPad! Barry Caplin Chief Information Security Officer MN Department of Human Services MN Gov’t. IT Symposium Session 100: Thurs.

• 17% have > 1 in their household• 37% - their partner uses it• 14% bought cause their kid has one• 19% considering purchasing another

http://today.yougov.co.uk/sites/today.yougov.co.uk/files/Tablet_ownership_in_households.pdf

Of iPad owners...

Page 13: You Got Chocolate On My iPad! Barry Caplin Chief Information Security Officer MN Department of Human Services MN Gov’t. IT Symposium Session 100: Thurs.
Page 14: You Got Chocolate On My iPad! Barry Caplin Chief Information Security Officer MN Department of Human Services MN Gov’t. IT Symposium Session 100: Thurs.
Page 15: You Got Chocolate On My iPad! Barry Caplin Chief Information Security Officer MN Department of Human Services MN Gov’t. IT Symposium Session 100: Thurs.
Page 16: You Got Chocolate On My iPad! Barry Caplin Chief Information Security Officer MN Department of Human Services MN Gov’t. IT Symposium Session 100: Thurs.
Page 17: You Got Chocolate On My iPad! Barry Caplin Chief Information Security Officer MN Department of Human Services MN Gov’t. IT Symposium Session 100: Thurs.
Page 18: You Got Chocolate On My iPad! Barry Caplin Chief Information Security Officer MN Department of Human Services MN Gov’t. IT Symposium Session 100: Thurs.

Our Story Begins...

Page 19: You Got Chocolate On My iPad! Barry Caplin Chief Information Security Officer MN Department of Human Services MN Gov’t. IT Symposium Session 100: Thurs.

PEDs

Computers

Device Convergence

Page 20: You Got Chocolate On My iPad! Barry Caplin Chief Information Security Officer MN Department of Human Services MN Gov’t. IT Symposium Session 100: Thurs.

Example

• The “PED” policy• Personal Electronic Device

• Acceptable use• Connections• Data storage

Page 21: You Got Chocolate On My iPad! Barry Caplin Chief Information Security Officer MN Department of Human Services MN Gov’t. IT Symposium Session 100: Thurs.

1 Day

Page 22: You Got Chocolate On My iPad! Barry Caplin Chief Information Security Officer MN Department of Human Services MN Gov’t. IT Symposium Session 100: Thurs.

5 Stages of Tablet Grief

• Surprise• Fear• Concern• Understanding• Evangelism

Page 23: You Got Chocolate On My iPad! Barry Caplin Chief Information Security Officer MN Department of Human Services MN Gov’t. IT Symposium Session 100: Thurs.

Considerations

Page 24: You Got Chocolate On My iPad! Barry Caplin Chief Information Security Officer MN Department of Human Services MN Gov’t. IT Symposium Session 100: Thurs.

What needs to change for “local” remote access?

Page 25: You Got Chocolate On My iPad! Barry Caplin Chief Information Security Officer MN Department of Human Services MN Gov’t. IT Symposium Session 100: Thurs.

BYO

Page 26: You Got Chocolate On My iPad! Barry Caplin Chief Information Security Officer MN Department of Human Services MN Gov’t. IT Symposium Session 100: Thurs.

BYO

BYOC or BYOD

Page 27: You Got Chocolate On My iPad! Barry Caplin Chief Information Security Officer MN Department of Human Services MN Gov’t. IT Symposium Session 100: Thurs.

Security Concerns

Page 28: You Got Chocolate On My iPad! Barry Caplin Chief Information Security Officer MN Department of Human Services MN Gov’t. IT Symposium Session 100: Thurs.

Data Leakage

Page 29: You Got Chocolate On My iPad! Barry Caplin Chief Information Security Officer MN Department of Human Services MN Gov’t. IT Symposium Session 100: Thurs.

Unauthorized Access

Page 30: You Got Chocolate On My iPad! Barry Caplin Chief Information Security Officer MN Department of Human Services MN Gov’t. IT Symposium Session 100: Thurs.

“Authorized” Access

Page 31: You Got Chocolate On My iPad! Barry Caplin Chief Information Security Officer MN Department of Human Services MN Gov’t. IT Symposium Session 100: Thurs.

Risk v Hype

Page 32: You Got Chocolate On My iPad! Barry Caplin Chief Information Security Officer MN Department of Human Services MN Gov’t. IT Symposium Session 100: Thurs.
Page 33: You Got Chocolate On My iPad! Barry Caplin Chief Information Security Officer MN Department of Human Services MN Gov’t. IT Symposium Session 100: Thurs.
Page 34: You Got Chocolate On My iPad! Barry Caplin Chief Information Security Officer MN Department of Human Services MN Gov’t. IT Symposium Session 100: Thurs.

How can we do BYOC?

Page 35: You Got Chocolate On My iPad! Barry Caplin Chief Information Security Officer MN Department of Human Services MN Gov’t. IT Symposium Session 100: Thurs.

Method 1 - Sync

• Direct or Net ConnectIssues:• Need Controls – a/v, app install control,

filtering, encryption, remote detonation• Authentication – 2-factor?• Leakage!• Support

Page 36: You Got Chocolate On My iPad! Barry Caplin Chief Information Security Officer MN Department of Human Services MN Gov’t. IT Symposium Session 100: Thurs.

Method 2 – ssl vpn• Citrix or similarPros:• Leakage – no remnants; disable screen

scrape, local save, print• Reduced support needed• Web filtering coveredIssues:• Unauthorized access still an issue; User

experience; Support

Page 37: You Got Chocolate On My iPad! Barry Caplin Chief Information Security Officer MN Department of Human Services MN Gov’t. IT Symposium Session 100: Thurs.

Method 3 – data/app segregation• Encrypted sandbox• Separate work and home• Many productsPros:• Better user experience• Central management/policy• Many products – local/cloud• Leakage – config separation, encryptionIssues: access ; support; cloud issues

Page 38: You Got Chocolate On My iPad! Barry Caplin Chief Information Security Officer MN Department of Human Services MN Gov’t. IT Symposium Session 100: Thurs.

DHS view

• Policy• Supervisor

approval• Citrix only• No Gov't records

on POE (unencrypted)

• 3G or wired

• Guest wireless• 802.1x• FAQs for

users/sups• Metrics

Page 39: You Got Chocolate On My iPad! Barry Caplin Chief Information Security Officer MN Department of Human Services MN Gov’t. IT Symposium Session 100: Thurs.

Other Issues

• Notes or manually entered data• Enterprise email/OWA• Discovery• Voicemail/video

Page 40: You Got Chocolate On My iPad! Barry Caplin Chief Information Security Officer MN Department of Human Services MN Gov’t. IT Symposium Session 100: Thurs.

The Future

• More tablets/phones/small devices• More “slim” OS's – chrome, android,

ios, etc• Cost savings/stipend?• Cloud• User Experience – Citrix GoldenGate,

Divide, Good• BES Fusion

Page 41: You Got Chocolate On My iPad! Barry Caplin Chief Information Security Officer MN Department of Human Services MN Gov’t. IT Symposium Session 100: Thurs.

Capabilities to Consider

• Device encryption• Transport encryption• Complex PWs/policy• VPN support• Disable camera• Restrict/block apps• Anti-malware InfoWorld March 2011 MDM Deep

Dive

• Restrict/block networks

• Remote lockout• Remote/selected wipe• Policy enforcement• OTA management• 2-factor/OTP

Page 42: You Got Chocolate On My iPad! Barry Caplin Chief Information Security Officer MN Department of Human Services MN Gov’t. IT Symposium Session 100: Thurs.

Discussion…

Slides at http://slideshare.net/bcaplin

[email protected]

[email protected], @bcaplin, +barry caplin