Educause Security Discussion mailing list archives

Re: Where do you stand? --- University policy on Jail broken mobile device access to secure networks.


From: "Ejike, Emechete C." <EEjike () ODU EDU>
Date: Fri, 30 Mar 2012 16:51:31 -0400

Thanks Jane, as you indicated, the jury is still out on such decisions. If you read up on my follow up responses, you 
would notice that a 'pay to play' approach is what may finally come out of it. In this regard, we intend to define some 
level/state of 'device security fidelity' that reflects a  threshold of acceptable standards for systems prior to 
'access permission grants' on these secure/elevated data domains. Strategically, an appropriate system/network 
segmentation should be in place. Gladly, We have achieved this in our environment. Obviously, we do not intend to 
prevent general network access. There are authenticated DMZ'ed wireless segments still providing resources such as 
simple wireless access to the outside. However, the general view of Jail broken systems in secure segments seems to 
garner different opinions especially since mobile devices and their related security structure is still a burgeoning 
field. This is evident from the various responses received to this question. The true take might be that from an SME. A 
general reaction is to simply decline access to JB devices however, as everyone would ask --Are JB devices more of a 
security risk?--. Since this is yet to be seen, the view may be to simply err on the side of caution but Should we 
prevent access  to a legalized form of device unlocking performed on a personal device? The question is still under 
scrutiny.


--
Eme

On Mar 30, 2012, at 2:49 PM, "Rosenthal, Jane E." <jer () ku edu<mailto:jer () ku edu>> wrote:

Eme,
We are considering an MDM solution and with any of this brave new world I would suspect the answer is "it depends".  
For instance, are you tracking that information in an MDM solution on campus?  If so, then you have knowledge of the 
jailbreak and the threat.  But if it is BYOD that twists it a bit.

Our discussions are still in process, but certainly the notice to the community and consent--if you're on our resources 
using our data, then you should agree to our terms, may be the route you want to consider.  But we have no official 
position as yet.  I personally am a big believer in transparency--if the user knows (really knows, not hidden in 42 
pages of agreement) then its incumbent upon them to agree and hook-on or disagree and not-hookon.

But the jury is still out and we will see.  I would be interested in what you hear/see in the MDM environment.



Jane Rosenthal
Director I KU Privacy
Office of the Provost
The University of Kansas

Tel +1.785.864.9528 I Fax 1.785.864.4463
jer () ku edu<mailto:jer () ku edu> I <http://privacy.ku.edu> privacy.ku.edu<http://privacy.ku.edu>

This message may be confidential and is only for the intended recipient. If you receive it in error, please delete it 
and attachments from all systems/memory and notify the sender ASAP.  Thank you.


-----Original Message-----
From: Eme Ejike [mailto:eejike () ODU EDU]
Sent: Thursday, March 29, 2012 10:05 AM
Subject: Where do you stand? --- University policy on Jail broken mobile device access to secure networks.

This is certainly interesting. I believe we all have some wonderful opinions.......

BYOD is here with all the intricacies involved in generating an apt SLA model for such devices on campus.
As part of the MDM service push for these devices, policies, standards and guidelines need to be defined to build a 
solid foundation on our foray into this arena.
What do our members believe an official stance on jail-broken devices should be?
Bearing in mind that our objectives are to provide security conscious access when on campus (i.e connected to an 
elevated access SSID with a purview into secure segments of the network --Network shares, ERP applications.. etc).

A reference on some industry SME view would help in supporting your response.



Sincerely,

Eme Ejike
OCCS, ITSO Supervisor
Old Dominion University

<CANIT-VOTING-LINKS-635686800-4181449a730b.txt>

Current thread: