Educause Security Discussion mailing list archives
Re: Where do you stand? --- University policy on Jail broken mobile device access to secure networks.
From: "Ejike, Emechete C." <EEjike () ODU EDU>
Date: Fri, 30 Mar 2012 16:51:31 -0400
Thanks Jane, as you indicated, the jury is still out on such decisions. If you read up on my follow up responses, you would notice that a 'pay to play' approach is what may finally come out of it. In this regard, we intend to define some level/state of 'device security fidelity' that reflects a threshold of acceptable standards for systems prior to 'access permission grants' on these secure/elevated data domains. Strategically, an appropriate system/network segmentation should be in place. Gladly, We have achieved this in our environment. Obviously, we do not intend to prevent general network access. There are authenticated DMZ'ed wireless segments still providing resources such as simple wireless access to the outside. However, the general view of Jail broken systems in secure segments seems to garner different opinions especially since mobile devices and their related security structure is still a burgeoning field. This is evident from the various responses received to this question. The true take might be that from an SME. A general reaction is to simply decline access to JB devices however, as everyone would ask --Are JB devices more of a security risk?--. Since this is yet to be seen, the view may be to simply err on the side of caution but Should we prevent access to a legalized form of device unlocking performed on a personal device? The question is still under scrutiny. -- Eme On Mar 30, 2012, at 2:49 PM, "Rosenthal, Jane E." <jer () ku edu<mailto:jer () ku edu>> wrote: Eme, We are considering an MDM solution and with any of this brave new world I would suspect the answer is "it depends". For instance, are you tracking that information in an MDM solution on campus? If so, then you have knowledge of the jailbreak and the threat. But if it is BYOD that twists it a bit. Our discussions are still in process, but certainly the notice to the community and consent--if you're on our resources using our data, then you should agree to our terms, may be the route you want to consider. But we have no official position as yet. I personally am a big believer in transparency--if the user knows (really knows, not hidden in 42 pages of agreement) then its incumbent upon them to agree and hook-on or disagree and not-hookon. But the jury is still out and we will see. I would be interested in what you hear/see in the MDM environment. Jane Rosenthal Director I KU Privacy Office of the Provost The University of Kansas Tel +1.785.864.9528 I Fax 1.785.864.4463 jer () ku edu<mailto:jer () ku edu> I <http://privacy.ku.edu> privacy.ku.edu<http://privacy.ku.edu> This message may be confidential and is only for the intended recipient. If you receive it in error, please delete it and attachments from all systems/memory and notify the sender ASAP. Thank you. -----Original Message----- From: Eme Ejike [mailto:eejike () ODU EDU] Sent: Thursday, March 29, 2012 10:05 AM Subject: Where do you stand? --- University policy on Jail broken mobile device access to secure networks. This is certainly interesting. I believe we all have some wonderful opinions....... BYOD is here with all the intricacies involved in generating an apt SLA model for such devices on campus. As part of the MDM service push for these devices, policies, standards and guidelines need to be defined to build a solid foundation on our foray into this arena. What do our members believe an official stance on jail-broken devices should be? Bearing in mind that our objectives are to provide security conscious access when on campus (i.e connected to an elevated access SSID with a purview into secure segments of the network --Network shares, ERP applications.. etc). A reference on some industry SME view would help in supporting your response. Sincerely, Eme Ejike OCCS, ITSO Supervisor Old Dominion University <CANIT-VOTING-LINKS-635686800-4181449a730b.txt>
Current thread:
- Where do you stand? --- University policy on Jail broken mobile device access to secure networks. Eme Ejike (Mar 29)
- Re: Where do you stand? --- University policy on Jail broken mobile device access to secure networks. Brian Helman (Mar 29)
- Re: Where do you stand? --- University policy on Jail broken mobile device access to secure networks. Ejike, Emechete C. (Mar 29)
- Re: Where do you stand? --- University policy on Jail broken mobile device access to secure networks. Brian Helman (Mar 29)
- Re: Where do you stand? --- University policy on Jail broken mobile device access to secure networks. John Ives (Mar 29)
- Re: Where do you stand? --- University policy on Jail broken mobile device access to secure networks. Brian Helman (Mar 29)
- Re: Where do you stand? --- University policy on Jail broken mobile device access to secure networks. Eme Ejike (Mar 29)
- Re: Where do you stand? --- University policy on Jail broken mobile device access to secure networks. Ejike, Emechete C. (Mar 29)
- Re: Where do you stand? --- University policy on Jail broken mobile device access to secure networks. Brian Helman (Mar 29)
- <Possible follow-ups>
- Re: Where do you stand? --- University policy on Jail broken mobile device access to secure networks. Ejike, Emechete C. (Mar 30)
