BYOD Without BYO(In) Security – Cisco
February 28, 2012, RSA Conference, San Francisco— Continuing the discussion of BYO Devices into a secure network, Cisco
Daniel DeSantos and Nasrin Rezai from Cisco described their Sentry program. Increasing mobility brings new requirements to people, processes, and the ocean of security models. By ’15, there’ll be more than 1 billion wireless devices, and every person will have three or four of these mobile devices. The borders between work and consumer, employee and patient, and other areas are all dropping very rapidly.
Increasingly, social networks and work are overlapping leading to an increase in API based threats. More workers and contractors are bringing their own devices which is bringing more malware into the systems. As a result, enterprises have a need for invasive security for the cloud and for the BYOD community.
The evolution of identity and IT models needs to show capabilities for scalability. Now the IT organization must manage and service the owner proactively. They must have a foundational focus model and a strategy to incorporate single source identification into Federated identifications across all platforms. Systems require fine-grained policy management and fine-grained access an application control. In addition, the network operator must ensure all paths to the network are secure through various access controls and authorization techniques so that all data is protected.
For both BYOD and operations involving the cloud, access and identification are vital. The system must know if the person attempting access is a hacker, agent, vendor, or some other high-risk person. The highest level of access is granted to employees with trusted devices, but data segmentation is still required. Good practices also require zoning, so only individuals with privileges in that zone are allowed access to the data.
Users are grouped into various categories with the main ones being; trusted device and user, and untrusted. As a result, deployments require a large matrix to address all the variables of trusted, untrusted, on or off network, local or remote access, and many other device and individual characteristics. All of these functions require network control.
Cisco’s strategy on apps is to virtualize as much as possible, so nothing has correct access to any portions of the network. They also work to force security awareness on both the applications developers and the users. One significant change required was in policies. Now, Cisco can take over a device for forensics, independent of ownership. Some results of these changes include device count going up more than 50 percent while service calls have dropped by 24 percent. So they have seen savings because of their security monitoring.
By allowing users to bring their own devices, they’ve managed to increase visibility and provide more policy-based controls. IT had to change architectures and evaluate service deployments, but now have better identity management for all users. Adding mobility and security is not just looking at transactions, but requires scalable monitoring and intelligent changes to architectures and operating procedures.
Making significant network changes calls for a phased deployment and a clear roadmap to identify business changes, user awareness, planning, and anticipation of all implementation details. As people move to more mobile devices, their identity becomes the perimeter. To service their needs, the system must know who they are, what they are doing, and what they are doing with any data error accessing. When users access external services they create many internal and external identifications, so service providers and identity brokerages are becoming more important to help manage all these identities.
Policies have to be developed to address the separation of user and corporate functions and data. Some of these are privacy issues, and some are corporate needs. Critical and sensitive data must be encrypted while in transit, but they are using digital certificates and not double factors. Looking at other solutions such as on device encryption for all mobile devices


