Gartner: iPod, Portable Devices a Corporate Security Risk
TMO Reports - Gartner: iPod, Portable Devices a Corporate Security Risk
by , 5:00 PM EDT, July 7th, 2004
Companies should consider banning portable storage devices such as Apple's iPod from corporate personal computers because they can spread viruses or steal critical corporate data, according to the research company Gartner, Inc.
The report, obtained by The Mac Observer and issued this week, does not recommend outright the banning of such devices from office environments, but does make it clear that portable USB and FireWire-based products open up businesses to a whole range of risks and that the protection of sensitive information is more important than ever.
The report points out the wide range of such portable devices, including smart media cards, memory sticks, compact flash, keychain drives as well as portable MP3 players. Small portable storage products can bypass perimeter defenses like firewalls and introduce malware such as Trojans or viruses onto company networks, said the report.
"Companies are at risk of losing intellectual property and other critical corporate data," the report said. "Portable storage devices are ideal for anyone intending to steal sensitive and valuable data. Employees may also be responsible for losing data if they inadvertently mislay these devices."
Gartner recommends companies "forbid the use of uncontrolled, privately owned devices with corporate PCs." In addition, the company suggests the adoption of "personal firewalls to limit activity on USB ports", investigate products that can control ports selectively, and "consider employing mobile data protection products to encrypt corporate or sensitive data."
The report ends by telling businesses that they "must ensure that the right procedures and technologies are adopted to securely manage the use of portable storage devices like USB 'keychain' drives. This will help to limit damage from malicious code, loss of proprietary information or intellectual property, and consequent lawsuits and loss of reputation."
Observer Comments
from the "duh" department.
so you are saying that people who bring in virtually unlimited storage devices in their pockets are a risk for data theft? say it ain't so.
we can't bring any recordable media, cameras, or even have cassette recorders (or cell phones).
blah blah, nothing to see here.
Wed Jul 07, 2004 9:00 pm Subject: ummm....
Let's see...they make USB drives that look like pens and watches and have a significant download (or upload) capacity, and they are picking on the iPod (by name, btw.)....
If employees are going to steal information from a company, banning iPods isn't going to stop it, or even slow it down. There is the floppy disk, burning CDs, or just printing the stuff or photocopying. Or, if you want to go really hi-tech, attaching a collar to the monitor cable and transmitting the screen to be received elsewhere (and it doesn't take much to do that, btw. Anybody remember TEMPEST?)
Malicious attacks at the hardware level are very difficult to stop. The methods suggested by Gartner will also cause a great deal of heartburn with most corporate users. It is treating them all like criminals, which doesn't generally go over well. And it is nigh impossible with laptop users.
I work for a very large media company as a PHP and ASP developer. A few months after they hired me I purchase a brand new laptop. Without even asking or thinking twice I started bringing it to work and connecting it right into the network. My boss didn't say a word other than "hey, that's a damn fine laptop you have there!" Over the next few months, to make things easy for me, I had copied 100% of the content of the internal servers as well as making complete duplicates of the databases - over 50 Gig's in all - directly onto my laptop hard drive (it is an 80 gig drive). I do all my work on my laptop and then upload it to the server and database at work and untill recently hearing all this stuff about theft of code, etc, I never thought about what I was doing as being "bad." Now I'm left very uneasy as the realization hits that I have 100% of the intellectual property of my employer on my laptop. I think I'd better have a conference with my boss over this and figure out a way to resolve this before it becomes an issue of concern among upper management, all of whom obviously never thought about this as thumb drives and laptops are pretty commonplace at work.
Sun Jul 11, 2004 3:59 pm Subject:
Nice way to make copy and grab a headline. A greater security risk than a bored employee surfing the 'Net and visiting questionable site loaded with spyware, trojan horses, etc.? I don't think so.
How many organizations provide employees with a CD burner on their PC and a USB port that will handle a flash memory backup device?
Just another way to grab a headline.
Knowing human nature, banning iPods from the workplace will only increase the attraction and consumer demand.
Comments are currently closed. Please email the author instead.
Recent Headlines - Updated February 9th
- Tue, 4:19 PM
- Just a Thought - iPad: A Reason For Being
- 3:28 PM
- News - Google Lowers Nexus One “Equipment Recovery Fee” to $150
- 2:27 PM
- Deal Brothers - Refurbished 13” MacBook 2.13GHz Intel Core 2 Duo: $749
- 1:31 PM
- Jeff Gamet's Blog - Macworld Expo: It’s Our Show, Not Apple’s
- 10:38 AM
- Quick Look Review - Texas Tea for the iPhone and iPod touch
- 10:25 AM
- News - Apple Rolls Out Aperture 3 Video Tutorials
- 10:00 AM
- Hot Forum Topic - Backing Up Your iPhoto Library
- 9:35 AM
- Product News - Notebook, iThoughts Add TextExpander touch Support
- 9:00 AM
- Hidden Dimensions - The Killer Surprises Waiting for Steve Ballmer
- 8:50 AM
- Product News - Aperture 3 Adds Faces Support, More [Updated]
- 8:30 AM
- TMO Quick Tip - Fixing iPhone and MobileMe Sync Headaches
- 8:12 AM
- News - Apple Store Offline, Rumors Point to New Laptops
The Mac Observer Reader Specials
- TypeStyler For Mac OS X is Now Shipping! Download The Free Fully Functional 60 Day Tryout at www.typestyler.com
RamJet Memory: Mac Pro 8GB Kit $275.99, Mac Pro 4GB Kits $145.99! Sale on MacBook and MacBook Pro 8GB kits $459.99! MacBook, MacBook Pro, iMac Mac mini 4GB Kits for $113.99! 1TB SATA Hard Drives for $109.99! Click here- If you own a car, you need CarMD! Catch problems, estimate repairs and more. Now for Mac. $98.99 at www.CarMD.com Save $10 with code TMO1.
If you're using a Mac, then you've gotta check out Full Tilt Poker for Mac. This Full Tilt Poker bonus code does the unthinkable, it actually rewards!For the latest Apple products use Ciao, a price comparison website, to find laptops like MacBook Air. Then find the best prices on MP3 players and use our comparison tool to evaluate mobile phones like the Apple iPhone.
Laptop Hardware Provided by TechRestore - Overnight Mac & iPod Repairs.


