SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Integrating IT >> Project Management

Beware the pod people

Beware the pod people

By:  Cara Garretson  On: 30 Apr 2007 For: CIO Canada Creator

Are iPods really as innocent as they seem? Some believe that they pose a significant security risk to the organization. Here’s what you can do about it.

Are iPods really as innocent as they seem? Some believe that they pose a significant security risk to the organization. Here’s what you can do about it.

The recent buzz about security threats posed by iPods to corporations has reinforced the need for IT managers to treat these devices like any other removable media that employees with malicious intent can use to extract sensitive data.

Following the suggestion recently made by a security company that iPods be banned from the workplace until proper protection is in place, and the emergence of a proof-of-concept iPod virus, it would seem that iPods pose a particularly high risk to corporations that let employees wander into work with these devices strung to their ears. Those same devices that entertain workers during their commute can be used to copy personal or financial data, intellectual property and other sensitive information from corporate PCs, often without a trace. The idea of stealing corporate data with an iPod has gained so much attention lately that it’s even been given its own term: slurping.

“If you see someone walking in the door with an iPod they don’t look like a threat, but to me I see the ability to download reams of files, and it might just look like they’re downloading music,” says Jim Hereford, CEO of NextSentry, which suggested the iPod ban. “We’re not saying companies shouldn’t allow iPods, but they better have endpoint security on their desktops.” Endpoint security technology blocks information that’s been deemed sensitive from being copied onto removable media, e-mailed or printed.

But others say iPods pose no more risk of corporate data theft than a cell phone that can snap a photo of a computer screen or a thumb drive that slides into a shirt pocket. The issue is that organizations need to realize that iPods should be treated accordingly.

“Devices such as iPods and other MP3 players are basically storage devices; some can store substantial amounts of data and are innocuous enough that their presence is almost unnoticed in our daily lives,” says Tom Scocca, investigator and global security consultant for a large provider of microprocessor manufacturing technology. “Controls targeted at these devices should be based not on the type of device, but on the risk that companies are willing to accept by allowing any type of external storage device into the environment.”

iPods stand out from most other types of removable media because their intended use – to play music and videos – is entertainment, whereas a thumb drive, for example, is clearly designed to copy files.

“If you’re listening to a book or music, that’s not seen as a threat,” says Benjamin Powell, a network operations manager who formerly worked as a security analyst at a financial services firm. But organizations need to lay out clear policies regarding the type of corporate information that can and cannot be copied onto iPods, and even back it up with software that implements those policies, he says.


Sign up for our Newsletters












Print |  Views: 1103   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Cara Garretson Cara Garretson is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Content

Plugging leaks: Teach your employees about security risks
Plugging leaks: Teach your employees about security risksWhat enterprises can learn from casino security. Plus, why employees ignore basic security principles
iPods can pose risk to company security, warns CEO
iPods can pose risk to company security, warns CEOThe recent buzz about security threats posed by iPods to corporations has reinforced the need for IT managers to treat these devices like any other removable media that employees with malicious intent can use to extract sensitive data
Security survival tips for the Web 2.0 world
Security survival tips for the Web 2.0 worldHere are some tips for developing security policies and practices that best fit your company, including pointers for communicating these new Web 2.0 policies to workers
Novell gets in on endpoint market, buys Senforce
it'll be interesting to see in a year from now how many standalone endpoint security firms are left.
blog comments powered by Disqus