Compliance

Feature Article

What Really Is the "D" in BYOD?

The Bring Your Own Device (BYOD) trend is consuming lots of digital ink on blogs, IT managers are wrestling with the problems created by it, and a growing number of vendors are addressing the issue with innovative new solutions. But when we talk about the “Device” in BYOD, what do we really mean? I contend that BYOD should really be BYODA:  Bring Your Own Devices and Applications (remember, you saw it here first!).

The problems with BYOD in a device-only context are several:

  • IT must spend more of its already scarce time to manage employee-owned devices like iPhones, iPads, Android smartphones, Android tablets, etc., in addition to the devices they supply to employees. This consumes an increasing amount of staff time in IT departments that are already resource- and budget constrained.
  • More strategically, employee-owned devices that access corporate applications, download email, store attachments and the like are mini-repositories of sensitive and confidential information that can create a variety of compliance problems. For example, a lost device that cannot be remotely wiped (not all companies have yet implemented this capability) can create enormous data breach notification problems, not to mention the potential exposure of intellectual property.
  • Even for devices that are not lost, imagine going through an e-discovery, regulatory audit or similar exercise in which you have to identify, search and extract data from potentially thousands of devices that are spread around the globe.
  • When employees leave your company, you have to ensure that a) sensitive or confidential corporate data has been returned to the company along with the device itself and b) that copies are not stored in repositories outside of IT’s control.

How are these problems any different for an organization when users download Dropbox, share company files via Hotmail to get around file-size limits in the corporate email system, or post information to Twitter or Facebook? Fundamentally, the problems are the same for devices as they are for applications: IT must spend time managing/blocking/creating policies about these applications if they want to exercise any sort of control over the content stored or sent using them, they face compliance issues when data is stored in personal cloud repositories, they face the same kinds of search and extraction problems when going through e-discovery or regulatory audits, and they have no assurance that corporate content is not still somewhere in the cloud after an employee leaves.

In short, the BYOD problem is not really a device-focused issue, it’s part of a larger governance issue that encompasses both devices and potentially thousands of different (mostly cloud) applications.

By nature SMBs need the flexibility and productivity that personal devices now offer. But is the company at risk with the fast adoption of “consumer” BYOD practices? There was a time when...
Despite advocacy efforts to amend parts of CISPA—H.R.3523 Cyber Intelligence Sharing and Protection Act of 2011 (PDF)—the cybersecurity legislation passed the House of Representatives...
Osterman Research
Press reports of data breaches are all too common these days, with some breaches exposing millions of records to at least potential exposure to criminals and others. These breaches can be caused by...
Osterman Research
There are numerous stories in the press about companies who demand to see the Facebook profiles of job applicants or current employees. In some cases, employees have been denied employment,...
This week the Federal Trade Commission published what some call a landmark report, which offers best practices for businesses to protect the privacy of consumers. The commission’s “...
Osterman Research
I have been banging the email archiving drum for many years, urging organizations of all sizes and across all industries to archive their email. Just as individuals archive their tax and other...
Offering both convenience and an easy, informal way to exchange ideas and information, instant messaging (IM) is growing exponentially as a corporate communication tool. A 2010 report by a leading...
Messaging News is pleased to present the Messaging News 2012 Resource Directory—the 5th annual edition of our resource guide. Since the last publication, new companies have come on the scene,...
Osterman Research
Our research finds that many organizations don’t have the budget to address many of the problems they face, such as managing certificates in a careful and coordinated way, monitoring and archiving...
Syndicate content