Security Management - Managing Mobiles - Bring Your Own Device

29-Nov-2011

Managing Mobile Devices - Bring your own device

Mobile devices are changing the way many enterprises work, receive information, and remain competitive. The challenge is that the range of devices is growing as well as the number of individuals using personal devices for professional use. This poses a security and deployment issue for many organizations as they try to manage these mobile devices.

Managing mobile devices is increasingly complex and challenging. Organizations have traditionally supported BlackBerry devices with limited range outside of that. However, use of other devices, including the explosion of enterprise use of iPhone and iPad, means that organizations must identify ways to manage the whole environment. The other issue is that employees are using personal mobile devices, which causes information security concerns and vulnerabilities for many businesses.

During this seminar, we have presented an overview of mobile device management and security best practices. An integrated approach to mobile security including company security policies, training, and a mobile device management solution is critical for all enterprises. This will better enable IT staff to manage their deployed mobile devices, in-house apps, collect data points, as well as ensure overall fleet/device security.

In april 2011, Gartner published its Magic Quadrant for Mobile Device Management Software platforms. Some of the represented vendors have been asked to present their perspectives. But as usual, we won’t be limiting ourselves to the analysis of Gartner alone and let you decide for yourself which qualifyers need to be addressed in this extremely dynamic and fast evolving domain.
We’ve also included some system integrators, to present their experiences and perspectives of some of the various market players.

Finally, attendees were able to make an informed decision about managing mobile assets and information assets transported wirelessly.

Final Program Overview

A seminar with various perspectives and market updates.

09.00h : Registration & Welcome Coffee, Networking, opening demo platform

09.30h : Welcoming notes & introduction by Ulrich Seldeslachts, CEO LSEC

09.45h : The perspective from a security platform, managing information security throughout the enterprise up to the mobile devices, by David Van Damme, McAfee

Changing users, hypergrowth in devices and various other trends impact the mobile threat outlook. With Mobile Malware on the rise, appstores and apps that should not be trusted, handhelds will require mobile security handlings for information on the move and at rest. Adding to this the complexities of security management, key management and end point protection, proof that an integrated platform will be useful.

10.15h : The changing mobile landscape and the impact on business, it and security management. Perspectives on dealing with mobiles, by Ulrik Van Schepdael Mobco

Dealing with mobiles in an enterprise environment, from policy development, IT architecture, system integration and mobile devices management, up to implementation and dynamically defining polcy rules.
With experiences shared from implementations of MobileIron and Box.net.

11.00h : Mobile Device Management and BYOD, an insight in a mobile device management platform and market experiences from Airwatch, by Manu Luyten, On2It.

11.45h : From Mobile Device Management to Fourfold Secure Mobile Device Management (Enterprise Mobile Data Lost Prevention).
Managing mobile devices beyond the platform and looking into security, market experiences with Zenprise by John Ferguson, Zenprise & Gert Vanhaeght, Mobila

Today, everyone has a smartphone. For enterprise this brings a duty of care to secure and protect sensitive corporate and customer information. But the complexity of managing and securing multiple device types, often without direct contact, is a challenge many IT personnel do not want to face. This presentation will demonstrate the changing environment, and – as recently identified by the industry analysts - the most capable solution to manage and protect the enterprise you carry in your pocket.

John Ferguson is Director of Product Management responsible for the Zenprise’s Mobile Device Management (MDM) service offerings.  John has 20 years of experience in product management and operations leadership positions with leading security technology companies.  Prior to Zenprise, John worked for Symantec developing cloud based security solutions and data loss prevention products while at Vontu (acquired by Symantec in 2008).  Before joining Vontu, John was an early employee of VeriSign where he had both product management and operations roles, including overall responsibility for VeriSign’s IT infrastructure and operations groups.  John started his professional career at AT&T where he spent 6 years in operations, marketing, and finance positions.  John has a B.S. Degree in Electrical Engineering as well as a Masters of Business Administration Degree in Finance.

Short interactive demo by Liz Knight

Liz Knight is Senior Pre-sales Engineer and from origin comes from New Zealand. Liz has recently made the decision to move to the Netherlands to become an important part of the team to build Zenprise and its entity in the Benelux Region.  Prior to Zenprise Liz, worked for large Telco Carriers as Technical Manager dedicated her professional capabilities to the advancement of wireless mobile data technologies. Customers she worked with include the largest financial and government organizations in New Zealand as well as small to medium emerging businesses. Regardless of size or requirements she strive to ensure each and every customer gets the best out of their mobility investment

12.30h : networking lunch

13.30h : Managing security at all levels for all smart phones, by Fabrice Hatteville, Thales

The fast growth of the smart phone and tablet markets, both in terms of sold units and in terms of technical possibilities, has brought a number of new challenges to the companies.  On one side, professional users tend to use their smart devices for both their professional and private needs, resulting in a mix a sensitive and non sensitive data on a single device.  On the other side, the flexibility of these devices and the rich possibilities they offer in terms of applications, connectivity, ... make them a target of choice for potential attacks by viruses or others.  At the same time, the large variety of brands and models makes it difficult for ICT managers and security managers to follow on technological trends and to anticipate on threats.
There is thus a need for companies to put in place a flexible system allowing at the same time to give access to the company’s standard tools for operational needs, to ensure secure communication between the employees’ smart phones / tablets and the sensitive data in the company’s system and to protect the company’s assets from potential threats coming from private activity on the employee’s device.  This all while maintaining a user friendly and simple-to-use interface. An insight on how these issues can be solved and which solutions exist will be given.

14.15h : Strategies and tips to manage and secure SmartPhones in a context of accelerated consumerization, by Michel Lanaspeze, Sophos.

Mobility and consumerization are defining some of the most significant changes in computing since the shift from mainframe computers,
bringing promises of increased enablement, efficiency, but also new risks and threats.  We will review these trends, giving insights from SophosLabs on risks,
and present strategies and practical advices for organizations to manage SmartPhones and Tablets effectively in order to make BYOD a productive and secure reality.

About : Michel Lanaspèze is Marketing & Communication Manager for Sophos Western Europe, with 24 years of experience in the IT industry,
and the past 15 years dedicated to the IT Security sector.  Michel Lanaspèze holds an Engineering degree from Telecom ParisTech
and an MBA degree from INSEAD.

15.00h : Coffee Break & Networking

15.30h : Integrating tablets Successfully in your Business Environment, The perspective from an operator using various mobiles, by Jean-Luc Delvaux, Belgacom.

In this presentation we will first review the various mobility trends and challenges and introduce the potential solutions.  Then we will discuss the real-life case of belgacom. Indeed, Belgacom has equipped all its sales force with tablets in 2011. We will discuss the choices that had to be made to make this initiative successful.

About : Jean-Luc has been working for Telindus International since 2001 (acquired by Belgacom in 2006) where he has been responsible for the ICT Security Strategy and for the development of the Security business internationally. In this capacity, he is in charge of developing Telindus’ security solutions and services portfolio as well as new market segments and geographies. Jean-Luc has more than 20 years of experience in the international ICT Services industry and close to 15 years more specifically in the Risk and Security domains. Prior to joining Telindus International, Jean-Luc has been active in various responsibility roles within Dimension Data, such as developing internationally the professional training business unit (NetBrain).

16.15h : Making all come together from a Security Management perspective. Closing Notes & Key Learnings of the day, by Steven Ackx, Ascure a full subsidiary of PWC Advisory Services

It’s not all about the technology and the threats. Those are some of the reasons and the how to deal with those threats and operating management of mobiles internally. Managing mobiles and mobile security is also about management and the way to get this included and embraced by the organization, the executives and employees. Risks have to be re-aligned, Security policies need to be adapted, procedures should be revisited and controls should be set in place or changed. Steven will try to make the connection of the technology perspective into the operations, and making sense for management.

About : Steven Ackx is a certified senior level consultant with extensive experience in Operational Risk Management, ICT- and Information Security related disciplines at the strategic, tactical, operational and technical level. Throughout his career he has focused on Information Security Governance, Information Security Management, Mobile Security, Mobile Payments, Information Risk Management, Education and Awareness Program.
At Ascure he is also managing the Ascure Academy, Marketing, Communication and Supporting Services activities. He is also the CEO of the BCM Academy Belgium.
Ascure is a full subsidiary of PwC Advisory Services cvba/scrl.

Also Mobile Management marketplace, meet the various vendors and decide for yourself.

Practical Details

This event took place November 29th, 2011 at Bremberg, Haasrode

Register Now

Register is now closed for Mobile Device Management 2011. You can already show your interest in Mobile Security Management 2012.

This event was free to participate to LSEC Members, LSEC partners and partner Members, Agoria Members, ECSA Members.
Free to participate to any others when subscribed before October 30th. After that date, subscription fee of 100 €.
Non-Cancellation fee of 150 €, upon no cancellation at least 1 day before the event and non-appearance.

This event was supported by CA Technologies.
It includes LSEC Expert Members Mobila, Mobco, Belgacom, McAfee, Sophos and Ascure - PWC.
This event has been supported by INTERREG IVb, in partnership with TeleTrusT, SITC, Systematic Paris Region and nGage Solutions.

About the organizers :
This event is organized by LSEC, a not-for-profit association focused on Information Security in Belgium. LSEC has been organizing over the last couple of years over 100 highly professional information security oriented activities. LSEC is a founding member of the European Security Innovation Network, a project supported by the European Commission through the INTERREG IVb program that supports innovative developments in the North Western European region in Security. With its partners Systematic Paris region in France, SITC in the UK and TeleTrusT in Germany, LSEC welcomes the active participation of companies to participate in the discussion of potential threats, challenges and opportunities for companies in the domain of Security, or to the enterprise market and government institutions. 

Are you a leader in Security ? Do you want to share your expertise and join the Leaders in Security as a Core Expert Member ?
Contact us via email! Or call +32.16.32.85.41 for a direct contact and more information.
An information set and your Membership Welcome Pack awaits you.

 

Copyright LSEC vzw 2007-2008 with the support of the IWT.

LSEC vzw Kasteelpark 10 - 3001 Heverlee - VAT BE BE 478 045 395 - fax. +32.16.32.19.69 - info @ lsec.be

<< May 2012 >>

S M T W T F S
29 30 1 2 3 4 5
6 7 8 9 10 11 12
13 14 15 16 17 18 19
20 21 22 23 24 25 26
27 28 29 30 31 1 2

Expert: Cognitive Security

Providing detailed intelligence against highly sophisticated network attacks.

Expert: Courion

Leader in IAM Solutions

Expert: Oracle

Oracle Belgium & Luxemburg

Expert: Option

Wireless data security enablers

Expert: TNO

TNO Research and Innovation

Expert: Control & Protection

Automatisering SCADA, PLC; Meettoestellen en brandbeveiliging

Expert: Thales Group

Thales Group

Expert: On2It

Smart IT Security We Are On To It

Expert: Mobco

Mobile Fleet Management

Expert: TITANS

TITANS ICT Consulting

Expert: G Data

G Data Anti Virus Solutions

Expert: Outpost 24 - Vulnerability Management Made Easy

Outpost 24 - Vulnerability Management Made Easy

Expert: Regify - Trusted and Binding Secure eMail

Regify - Trusted and Binding Secure eMail

Expert: Mobila - Mobile Enterprise Applications

Mobile Enterprise & Applicatinos

Expert: Lancelot Institute

Lancelot Institute - Training in Information Security, IT- Risk & IT - Auditing

Expert: CSI Tools

CSI tools is an expert software solution provider specialized in powerful tools for IT architects and auditors who are focused on maximizing GRC project development efficiency in SAP environments.

Expert: Intrinsic-ID

Content Protection, Unique Device Identification, Key Storage, PUF Physical Unclonable Functions

Expert: Belgacom ICT

Belgacom ICT Security Solutions for Large, Medium and Small Enterprises

Expert: Qualys

On Demand Vulnerability Management and Policy Compliance

Expert: Trend Micro

Securing your web world

Expert: Egemin

Egemin provides process and handling automation engineering and Secures Industry Automation

Expert: AEP Networks

More than 60 countries ... protected by AEP Networks

Expert: Palo Alto Networks

Next Generation Firewalls

Expert: Atos Origin Belgium & Luxemburg

A leading IT services provider. Ranks 1 in telecom outsourcing. Via Atos Worldline specialized in financial transactions.

Expert: Websense

Leading provider of unified content security

Expert: CA Technologies

Protect your critical IT assets, achieve sustainable regulatory compliance, reduce IT administration costs and enable new business opportunities with our security management products.

Expert: CA Technologies

Protect your critical IT assets, achieve sustainable regulatory compliance, reduce IT administration costs and enable new business opportunities with our security management products.

Expert: Axl-Trax

axl & trax are highly qualified experts in providing leading edge GRC services for SAP

Expert: VintiQ

VintiQ - Security Management Services

Expert: T-Systems Belgium

T-Systems is Deutsche Telekom's corporate customer arm.

Expert: LIN.K nv - LINKID

LIN.K is a provider of online user authentication, identification with the system LINKID

Expert: Devoteam Belgium

Devoteam Belgium, one of the major European ICT consultancy specialists with offices in 23 countries

Expert: CHB Technologies - Celadon Hailstone Biometrics

Celadon Bailstone Biometrics

Expert: Barracuda Networks

Worldwide supplier of email and internet security

Expert: Sophos

Sophos is the Utimaco is a leading global provider of data security solutions, enabling mid- to large-size organizations to safeguard their data assets against intentional or unintentional data loss, and to comply with privacy laws.

Expert: Dimension Data

Dimension Data

Expert: Bull

Bull

Expert: Check Point Software Technologies

Check Point Software Technologies

Expert: MMS-Secure

MMS-Secure nv, a distributor with a specific focus on network and systems security

Expert: F-Secure Corporation

F-Secure - Fastest Focused Anti-Virus Protection

Expert: C-Cure

C-Cure are Information Security architects already since 1998

Expert: IS4U

IS4U - Cronos specializes in Identity and Access Management

Expert: UCL Crypto Group

The Crypto Group of UCL, the UC of Louvain-la-Neuve is a research group specialized in cryptography and information security.

Expert: eID Company

eID company provides a flexible easy to integrate eID in any web application. Access to eID as a webservice.

Expert: ACA IT-Solutions

ACA IT-Solutions, end to end IT solutions and IDM Expert. Probably the largest and most successful independent J2EE solution provider.

Expert: RSA - Security Division of EMC

RSA - The Security Division of RSA. One of the leading companies in the world in IT Security. Enterprise wide Data Security solutions, suites and Services.

Expert: Unisys

Security Unleashed – At Unisys, we’re looking at security in an entirely new way.Security is no longer a defensive measure. It’s an enabling catalyst for achievement.Unisys Secure Business Operations help to unleash your full potential.

Expert: Zion Security

ZION SECURITY is the leading European application security company. Our mission is to secure your business value by securing your business applications.

Expert: Zetes

For those who want to see the difference!

Expert: Vasco

VASCO designs, develops, markets and supports patented User Authentication products for e-business and e-commerce.

Expert: SUN Microsystems

Everyone and everywhere connected to the network.

Expert: Security4Biz

Security4Biz offers ICT security consultancy services.

Expert: SecurIT

The value proposition to our customers is the competence and experience of highly qualified people, combined with best-in-class solutions from leading suppliers, and our entire focus on Identity and Access Management.

Expert: Sealed

Expert in implementation of e-Security, e-Proofs and e-ID within the management of business & document flows & processes, or within the management of your enterprise content in the broad sense.

Expert: McAfee

McAfee is the world largest dedicated security companY;

Expert: NXP (founded by Philips)

Sense & simplicity. Help customers to transform initial ideas into competitive products and cost-efficient manufacturing solutions within healthcare, lifestyle and technology.

Expert: KPMG

PMG Information Risk Management (IRM) focuses on inherent risks in technology systems used to support your business objectives and grow your business.

Expert: EMC2

EMC Corporation is the world's leading developer and provider of information infrastructure technology and solutions.

Expert: Deloitte

In addition to the qualities of a leading Belgian audit and consulting firm, Deloitte is different through the values it shares daily with clients and employees.

Expert: Certipost

Specialist in secured electronic document exchange for companies, the state, and for residential customers.

Expert: Ascure

World class information risk management services!

Expert: Verizon Business

Verizon Business is now the leading provider of managed security services worldwide with acquisition of Cybertrust.

Expert: K.U. Leuven

Computer Security and Industrial Cryptography (COSIC): Cryptography to protect data against passive and active fraud.

Expert: ATOS Worldline nv

Specialist in end-to-end secure payment systems.

Expertise: UTM

UTM - Unified Threat Management

Expertise: End Point Security

End Point Security

Expertise: DLP - Data Leakage, Data Loss Prevention and Protection

DLP - Data Leakage, Data Loss Prevention and Protection

Expertise: SOA - Service Oriented Architectures

Expertise: Identity Management

Identity Management (IdM) enables organizations to facilitate and control their users' access to critical online applications and resources — while protecting confidential personal and business information from unauthorized access

Expertise: Crypto

Cryptography - Cryptografie - Cryptographie

Expertise: Secure Application Development

Secure Application Development. Security does not only start at user name and password login, from the first entry of a software security needs to be integrated.

Expertise: RFID

passive and active low-cost wireless tags

Expertise: Application Security

encompasses measures taken to prevent exceptions in the security policy of an application or the underlying system

Expertise: Wireless Security

Expertise: Appliances

protect computer networks from unwanted data traffic, intruders, email spam, enforce policies, and may also be used to create and manage VPNs.

Expertise: Access Control

the ability to permit or deny the use of something by someone.

Expertise: Risk and Vulnerability Assessment

process of identifying and quantifying vulnerabilities in a system..Cataloging assets and capabilities (resources) in a system

Expertise: Penetration Testing

A method of evaluating the security of a computer system or network by simulating an attack by a malicious user, commonly known as a hacker.

Expertise: Physical Security

describes measures that prevent or deter attackers from accessing a facility, resource, or information stored on physical media. It can be as simple as a locked door or as elaborate as multiple layers of armed guardposts.

Expertise: Remote Access

computer program that lets you access your PC from another PC via the Internet, LAN, or phone connection and work on your computer ...

Expertise: Security Policy

security policy is a definition of what it means to be secure for a system, organization or other entity. For systems, the security policy addresses constraints on functions and flow among them, constraints on access by external systems and adversaries

Expertise: Anti-Virus

Software that detects, repairs, cleans, or removes virus-infected files from a computer.

Expertise: Spyware

Software that covertly gathers user information through the user's Internet connection without his or her knowledge, usually for advertising purposes.

Expertise: Authorization

The process of enforcing policies: determining what types or qualities of activities, resources, or services a user is permitted. Usually, authorization occurs within the context of authentication.

Expertise: Authentication

Provides a way of identifying a user, typically by having the user enter a valid user name and valid password before access is granted. The process of authentication is based on each user having a unique set of criteria for gaining access.

Expertise: Computer Virus

Program or programming code that replicates by being copied or initiating its copying to another program, computer boot sector or document.

Expertise: Smart Cards

smart card or chip card, is defined as any pocket-sized card with embedded integrated circuits which can process information such as a SIM for a mobile phone or an eID card

Expertise: UTM and Appliances

Unified threat management (UTM) is a term which is used to describe network firewalls that have many features in one box, for example junk e-mail filtering,or anti-virus capability, along with the traditional activities of a firewall.

Expertise: NAC

Network access control (NAC) is a method by which hardware and software grant access to enterprise network resources after first authorizing the user and device and verifying the device's compliance with the enterprise's security policy.

Expertise: Biometrics

Biometrics (ancient Greek: bios ="life", metron ="measure") is the study of methods for uniquely recognizing humans based upon one or more intrinsic physical or behavioral traits.

Expertise: DRM

Expertise: eID - Electronic Identity Cards

The electronic identity card (eID) is an official electronic proof of one's identity. It also enables the possibility to sign electronic documents with a legal signature.