Can an iPod bring down your company?

iPods need to be treated like any other removable media that can be used for malicious intent

The recent buzz about security threats posed by iPods to corporations has reinforced the need for IT managers to treat these devices like any other removable media that employees with malicious intent can use to extract sensitive data.

Following the suggestion recently made by a security company that iPods be banned from the workplace until proper protection is in place, and the emergence of a proof-of-concept iPod virus, it would seem that iPods pose a particularly high risk to corporations that let employees wander into work with these devices strung to their ears. Those same devices that entertain workers during their commute can be used to copy personal or financial data, intellectual property and other sensitive information from corporate PCs, often without a trace. The idea of stealing corporate data with an iPod has gained so much attention lately that it's even been given its own term -- slurping.

"If you see someone walking in the door [of a company] with an iPod they don't look like a threat, but to me I see the ability to download reams of files, and it might just look like they're downloading music," says Jim Hereford, CEO of NextSentry, which issued the suggested iPod ban and makes software that prevents employees from unauthorized copying of corporate data. "We're not saying companies shouldn't allow iPods, but they better have endpoint security on their desktops."

Endpoint security technology, available from NextSentry as well as handfuls of other companies in the monitoring, content-ware and data loss prevention spaces, is designed to solve the problem by blocking information that's been deemed sensitive from being copied onto removable media, e-mailed or printed. This way, employees can use their iPods in an office setting -- particularly important as corporations begin to look at the video devices as not just entertainment but potential training tools -- but won't be able to copy data onto the iPod unless authorized to do so.

But others say iPods pose no more risk of corporate data theft than a cell phone that can snap a photo of a computer screen or a thumb drive that slides into a shirt pocket. The issue is that organizations need to realize that iPods should be treated accordingly.

"Devices such as iPods and other MP3 players are basically storage devices; some can store substantial amounts of data and are innocuous enough that their presence is almost unnoticed in our daily lives," says Tom Scocca, investigator and global security consultant for a large provider of microprocessor manufacturing technology. "Controls targeted at these devices should be based not on the type of device, but on the risk that companies are willing to accept by allowing any type of external storage device into the environment."

iPods stand out from most other types of removable media because their intended use -- to play music and videos -- is entertainment, whereas a thumb drive, for example, is clearly designed to copy files.

"If you're listening to [an audio] book or music, that's not seen as a threat," says Benjamin Powell, a network operations manager who formerly worked as a security analyst at a financial services firm. But organizations need to lay out clear policies regarding the type of corporate information that can and cannot be copied onto iPods, and even back it up with software that implements those policies, he says.

Software that secures the endpoint is one option, says Scocca, but requires a lot of upfront work to ensure that the policies set regarding what can and cannot be copied don't interfere with an employee's ability to do their job. Instead, educating employees is the most effective thing companies can do, he says.

"We have to rely on our trusted employees," agrees David Jordan, CISO at Virginia's Arlington County. "The user is a very powerful antitheft tool; we keep them aware. Every day when they log on they agree to abide by our policies."

However, Jordan adds that if an employee comes in with malicious intent, "there's not much we're able to do about that except prosecute, and we have had people go to jail for breaking the rules."

Apple officials did not respond to inquiries asking if the company plans to add security features to iPods.

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.
Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Cara Garretson

Network World
Show Comments

Brand Post

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Aysha Strobbe

Microsoft Office 365/HP Spectre x360

Microsoft Office continues to make a student’s life that little bit easier by offering reliable, easy to use, time-saving functionality, while continuing to develop new features that further enhance what is already a formidable collection of applications

Michael Hargreaves

Microsoft Office 365/Dell XPS 15 2-in-1

I’d recommend a Dell XPS 15 2-in-1 and the new Windows 10 to anyone who needs to get serious work done (before you kick back on your couch with your favourite Netflix show.)

Maryellen Rose George

Brother PT-P750W

It’s useful for office tasks as well as pragmatic labelling of equipment and storage – just don’t get too excited and label everything in sight!

Cathy Giles

Brother MFC-L8900CDW

The Brother MFC-L8900CDW is an absolute stand out. I struggle to fault it.

Luke Hill

MSI GT75 TITAN

I need power and lots of it. As a Front End Web developer anything less just won’t cut it which is why the MSI GT75 is an outstanding laptop for me. It’s a sleek and futuristic looking, high quality, beast that has a touch of sci-fi flare about it.

Emily Tyson

MSI GE63 Raider

If you’re looking to invest in your next work horse laptop for work or home use, you can’t go wrong with the MSI GE63.

Featured Content

Product Launch Showcase

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?