SlideShare une entreprise Scribd logo
1  sur  11
Responsible Not Restrictive
Mike Brannon
Dir. Infrastructure & Security, National Gypsum




                                                  1
National Gypsum Company is a fully integrated building products manufacturer




Headquartered in Charlotte, NC
 with mines and quarries, and
 manufacturing plants across
        North America
                                                                          2
National Gypsum and MobileIron

                   Nov 2009
                                                June 2012
                (National Gypsum
                                                  (M2)
                buys MobileIron)

iPads sold by
                        0                       >70 million
    Apple


 MobileIron
                        7                          2300
 customers


 … countries            2                           32



… employees            39                          320




                                                              3
                    MobileIron - Confidential             3
National Gypsum Mobile Requirements

Business users pick devices they want (not Blackberry)


SECURE process to enable / allow BYOD phones, iPads


ActiveSync and Juniper VPN connections


DEVICE level security and respect for “employee data”
  – PIN/passcode, device / backup, encryption
  – NO jailbreaks, MDM and SW inventories


Elected NOT to use most “mobile intel” – employee issues
   – Using last location / international warning message

Next: PKI SCEP mgmt, app deployment coming, iOS domination

                                                             4
Evolving Mobile Strategy

FIRST:                 Email
It’s all about email all the time




    NEXT:              Personal tools
    Leverage the app store for personal tools
    •    Sales/service, office, plant, engineers – DIVERSITY



          NOW:            Connecting data
          Connect our data/processes with employees, partners, customers
          •   NGC4ME is .NET custom web app – one-stop shop
          •   SharePoint is private cloud/content manager/etc.
                                                                     5
Principles / Learning…

Do not custom develop unless absolutely required
  – Leverage smart devices and off-the-shelf components
  – Stay away from super customized work – takes resources
  – Approach as “Systems Integrator” – assemble proven components


Keep focused on USABLE solutions to business issues
  – “Voice of the Customer” as the priority guide!


Remember technically simple solutions are better (Agile/Nimble)
  – Cannot assume that “best” will always be “best”


Leverage existing technology components
   – Microsoft AD/PKI, Servers; Juniper VPN; .NET Development

Security cannot just say NO – offer the secure option

                                                                  6
What we implemented

ActiveSync email access – Exchange 2007/ISA then;
   – Now Exchange 2010 and Juniper/Junos Pulse
   – All devices “under management”; all users


Juniper – Junos Pulse VPN access (iPad/iOS) – SharePoint and .NET web
applications delivered (“NGC4ME”) -- SharePlus and Colligo Briefcase


Field sales / customer svc / marketing deployment
   – Collection of apps (BrainShark/SharePlus/Concur)
   – Now working on custom app / deployment / one click (NGC4ME)


Legal / security issues with some approaches
   – DropBox NOT permitted – Box.Com and SharePoint in use instead
   – Avoid “personal accounts” in favor of more “enterprise ready”
     answers


                                                                   7
High Level Architecture



                                                        PKI Server,
                                    MobileIron             HSM

iPad




                                                      NGC AD Servers   MobileIron Enrollment
iPhone,                           Juniper SSL VPN                      • Policy Checking
Android

                                                                       MDM Configuration
                                                                       • WiFi, VPN, Certs/Apps
                                            Exchange CAS
                      SharePoint / .NET       Mailboxes                Exchange CAS Sentry
                                              MI Sentry                • Email is „User Driver”

                                                                       Juniper VPN as Proxy
                                                                       • AD Integrated
                  SQL Databases
                                                                       SharePoint Portal/.NET
                                                                       • Windows Servers SQL
                                                                       • XML Interfaces M/F
                                          Mainframe

                                                                                               8
App Challenges - Responses


          Challenge                           Response

Beyond email, our employees         SharePoint is open, web
leverage shared content             oriented content manager

Apps deliver data into SharePoint   Users save data into team sites,
(Reports, Search-BCS)               workflow and email ties
                                    “Personal Cloud” based upon
                                    MySites and user profiles

Simple web forms                    SharePoint Lists – Mobile
                                    Safari OR Apps (see below)

Surveys, pictures and easy          Colligo, SharePlus, Filamente
analysis (More complex!)            and Docs2Go provide great
                                    tools

                                                                       9
Core philosophy – Responsible but not restrictive

Vision: “Do the right thing for the right reason” (Security, risk &
compliance – collaboration with the business)


     Security cannot just say NO … Must offer a secure option

Business Need             Options Proposed           Response / Solution

Easy-to-use cloud       DropBox, iCloud, various            Internal users:
storage                    “personal” storage           SharePoint MySites
                         accounts and services          External: Box.Com


Full-fidelity             Keynote conversion,            Business account:
presentations with        personal Slideshare,                 BrainShark
animations                    SlideShark



                                                                        10
Thank you




            11

Contenu connexe

Tendances

Worklight 5.0 Webinar 7 12 V2
Worklight 5.0 Webinar 7 12 V2Worklight 5.0 Webinar 7 12 V2
Worklight 5.0 Webinar 7 12 V2
gaborvodics
 
Mobile device and application management
Mobile device and application managementMobile device and application management
Mobile device and application management
Amplexor
 
Introduction to IBM Worklight: Building and connecting cross-platform mobile ...
Introduction to IBM Worklight: Building and connecting cross-platform mobile ...Introduction to IBM Worklight: Building and connecting cross-platform mobile ...
Introduction to IBM Worklight: Building and connecting cross-platform mobile ...
Jeremy Siewert
 
FOREST - VMware Zimbra Collaboration Server Overview
FOREST -  VMware Zimbra Collaboration Server OverviewFOREST -  VMware Zimbra Collaboration Server Overview
FOREST - VMware Zimbra Collaboration Server Overview
Muhammad Alif Abdul Malek
 
IBM Worklight - Technical Overview
IBM Worklight - Technical OverviewIBM Worklight - Technical Overview
IBM Worklight - Technical Overview
IIC_Barcelona
 
Worklight nitin nm
Worklight nitin nmWorklight nitin nm
Worklight nitin nm
Nitin Gaur
 
Mobile and IBM Worklight Best Practices
Mobile and IBM Worklight Best PracticesMobile and IBM Worklight Best Practices
Mobile and IBM Worklight Best Practices
Andrew Ferrier
 

Tendances (20)

Designing Mobile Applications
Designing Mobile ApplicationsDesigning Mobile Applications
Designing Mobile Applications
 
LocalSocial Overview Q409v3
LocalSocial Overview Q409v3LocalSocial Overview Q409v3
LocalSocial Overview Q409v3
 
Sybase SUP Mobil Uygulama Geliştirme Genel Bilgilendirme
Sybase SUP Mobil Uygulama Geliştirme Genel BilgilendirmeSybase SUP Mobil Uygulama Geliştirme Genel Bilgilendirme
Sybase SUP Mobil Uygulama Geliştirme Genel Bilgilendirme
 
Styr mobile enheder med Mobile Device Management, Martin Vittrup, IBM
Styr mobile enheder med Mobile Device Management, Martin Vittrup, IBMStyr mobile enheder med Mobile Device Management, Martin Vittrup, IBM
Styr mobile enheder med Mobile Device Management, Martin Vittrup, IBM
 
Blackberry
BlackberryBlackberry
Blackberry
 
Worklight 5.0 Webinar 7 12 V2
Worklight 5.0 Webinar 7 12 V2Worklight 5.0 Webinar 7 12 V2
Worklight 5.0 Webinar 7 12 V2
 
Nokia E7 Smartphone: Nokia and IBM Co-operation
Nokia E7 Smartphone: Nokia and IBM Co-operationNokia E7 Smartphone: Nokia and IBM Co-operation
Nokia E7 Smartphone: Nokia and IBM Co-operation
 
Mobile device and application management
Mobile device and application managementMobile device and application management
Mobile device and application management
 
IBM Worklight-Overview
IBM Worklight-OverviewIBM Worklight-Overview
IBM Worklight-Overview
 
Introduction to IBM Worklight: Building and connecting cross-platform mobile ...
Introduction to IBM Worklight: Building and connecting cross-platform mobile ...Introduction to IBM Worklight: Building and connecting cross-platform mobile ...
Introduction to IBM Worklight: Building and connecting cross-platform mobile ...
 
FOREST - VMware Zimbra Collaboration Server Overview
FOREST -  VMware Zimbra Collaboration Server OverviewFOREST -  VMware Zimbra Collaboration Server Overview
FOREST - VMware Zimbra Collaboration Server Overview
 
Genesis Overview Slides from Adobe MAX 2008
Genesis Overview Slides from Adobe MAX 2008Genesis Overview Slides from Adobe MAX 2008
Genesis Overview Slides from Adobe MAX 2008
 
IBM Worklight - Technical Overview
IBM Worklight - Technical OverviewIBM Worklight - Technical Overview
IBM Worklight - Technical Overview
 
Squared roof technology
Squared roof technologySquared roof technology
Squared roof technology
 
IBM MobileFirst - Hybrid Application Development with Worklight
IBM MobileFirst - Hybrid Application Development with WorklightIBM MobileFirst - Hybrid Application Development with Worklight
IBM MobileFirst - Hybrid Application Development with Worklight
 
Blackberry technology
Blackberry technologyBlackberry technology
Blackberry technology
 
Envision IT - Designing your SharePoint Extranet to work for you
Envision IT - Designing your SharePoint Extranet to work for youEnvision IT - Designing your SharePoint Extranet to work for you
Envision IT - Designing your SharePoint Extranet to work for you
 
Securing the Mobile enterprise
Securing the Mobile enterpriseSecuring the Mobile enterprise
Securing the Mobile enterprise
 
Worklight nitin nm
Worklight nitin nmWorklight nitin nm
Worklight nitin nm
 
Mobile and IBM Worklight Best Practices
Mobile and IBM Worklight Best PracticesMobile and IBM Worklight Best Practices
Mobile and IBM Worklight Best Practices
 

Similaire à Mobile Device Security - Responsible Not Repressive

We4IT lcty 2013 - keynote - ibm messaging & collaboration roadmap 2013
We4IT lcty 2013 - keynote - ibm messaging & collaboration roadmap 2013We4IT lcty 2013 - keynote - ibm messaging & collaboration roadmap 2013
We4IT lcty 2013 - keynote - ibm messaging & collaboration roadmap 2013
We4IT Group
 
Codestrong 2012 breakout session the role of cloud services in your next ge...
Codestrong 2012 breakout session   the role of cloud services in your next ge...Codestrong 2012 breakout session   the role of cloud services in your next ge...
Codestrong 2012 breakout session the role of cloud services in your next ge...
Axway Appcelerator
 
WSO2Con Asia 2014 - Embracing BYOD Trend Without Compromising Security, Emplo...
WSO2Con Asia 2014 - Embracing BYOD Trend Without Compromising Security, Emplo...WSO2Con Asia 2014 - Embracing BYOD Trend Without Compromising Security, Emplo...
WSO2Con Asia 2014 - Embracing BYOD Trend Without Compromising Security, Emplo...
WSO2
 
WSO2Con Asia 2014 - Embracing BYOD Trend Without Compromising Security, Emplo...
WSO2Con Asia 2014 - Embracing BYOD Trend Without Compromising Security, Emplo...WSO2Con Asia 2014 - Embracing BYOD Trend Without Compromising Security, Emplo...
WSO2Con Asia 2014 - Embracing BYOD Trend Without Compromising Security, Emplo...
WSO2
 
Dr. Michael Valivullah, NASS/USDA - Cloud Computing
Dr. Michael Valivullah, NASS/USDA - Cloud ComputingDr. Michael Valivullah, NASS/USDA - Cloud Computing
Dr. Michael Valivullah, NASS/USDA - Cloud Computing
ikanow
 

Similaire à Mobile Device Security - Responsible Not Repressive (20)

IBM Messaging and Collaboration Roadmap - Notes and Domino update - December ...
IBM Messaging and Collaboration Roadmap - Notes and Domino update - December ...IBM Messaging and Collaboration Roadmap - Notes and Domino update - December ...
IBM Messaging and Collaboration Roadmap - Notes and Domino update - December ...
 
Telecoms in the Clouds Issue 1
Telecoms in the Clouds Issue 1Telecoms in the Clouds Issue 1
Telecoms in the Clouds Issue 1
 
Symantec Enterprise Mobility Vision May 2012
Symantec Enterprise Mobility Vision May 2012Symantec Enterprise Mobility Vision May 2012
Symantec Enterprise Mobility Vision May 2012
 
Enterprise mobility management customer presentation december scripted
Enterprise mobility management customer presentation december scriptedEnterprise mobility management customer presentation december scripted
Enterprise mobility management customer presentation december scripted
 
01 introduction to darwino
01   introduction to darwino01   introduction to darwino
01 introduction to darwino
 
We4IT lcty 2013 - keynote - ibm messaging & collaboration roadmap 2013
We4IT lcty 2013 - keynote - ibm messaging & collaboration roadmap 2013We4IT lcty 2013 - keynote - ibm messaging & collaboration roadmap 2013
We4IT lcty 2013 - keynote - ibm messaging & collaboration roadmap 2013
 
Presentación Novedades vSphere 5.1
Presentación Novedades vSphere 5.1Presentación Novedades vSphere 5.1
Presentación Novedades vSphere 5.1
 
Design Considerations When Building Cross Platform Mobile Applications
 Design Considerations When Building Cross Platform Mobile Applications Design Considerations When Building Cross Platform Mobile Applications
Design Considerations When Building Cross Platform Mobile Applications
 
Codestrong 2012 breakout session the role of cloud services in your next ge...
Codestrong 2012 breakout session   the role of cloud services in your next ge...Codestrong 2012 breakout session   the role of cloud services in your next ge...
Codestrong 2012 breakout session the role of cloud services in your next ge...
 
Real World Identity Managment
Real World Identity ManagmentReal World Identity Managment
Real World Identity Managment
 
WSO2Con Asia 2014 - Embracing BYOD Trend Without Compromising Security, Emplo...
WSO2Con Asia 2014 - Embracing BYOD Trend Without Compromising Security, Emplo...WSO2Con Asia 2014 - Embracing BYOD Trend Without Compromising Security, Emplo...
WSO2Con Asia 2014 - Embracing BYOD Trend Without Compromising Security, Emplo...
 
WSO2Con Asia 2014 - Embracing BYOD Trend Without Compromising Security, Emplo...
WSO2Con Asia 2014 - Embracing BYOD Trend Without Compromising Security, Emplo...WSO2Con Asia 2014 - Embracing BYOD Trend Without Compromising Security, Emplo...
WSO2Con Asia 2014 - Embracing BYOD Trend Without Compromising Security, Emplo...
 
Mind the gap: Navigating the Security Challenges of BYOD
Mind the gap: Navigating the Security Challenges of BYODMind the gap: Navigating the Security Challenges of BYOD
Mind the gap: Navigating the Security Challenges of BYOD
 
Analyst field reports on top 15 MDM solutions - Aaron Zornes (NYC 2021)
Analyst field reports on top 15 MDM solutions - Aaron Zornes (NYC 2021)Analyst field reports on top 15 MDM solutions - Aaron Zornes (NYC 2021)
Analyst field reports on top 15 MDM solutions - Aaron Zornes (NYC 2021)
 
Bechtel On OpenID and OAuth from Cloud Identity Summit
Bechtel On OpenID and OAuth from Cloud Identity SummitBechtel On OpenID and OAuth from Cloud Identity Summit
Bechtel On OpenID and OAuth from Cloud Identity Summit
 
The Notes/Domino Application Development Competitive Advantage - IamLUG
The Notes/Domino Application Development Competitive Advantage - IamLUGThe Notes/Domino Application Development Competitive Advantage - IamLUG
The Notes/Domino Application Development Competitive Advantage - IamLUG
 
Database@Home - Data Driven Reference Architecture
Database@Home - Data Driven Reference ArchitectureDatabase@Home - Data Driven Reference Architecture
Database@Home - Data Driven Reference Architecture
 
Dr. Michael Valivullah, NASS/USDA - Cloud Computing
Dr. Michael Valivullah, NASS/USDA - Cloud ComputingDr. Michael Valivullah, NASS/USDA - Cloud Computing
Dr. Michael Valivullah, NASS/USDA - Cloud Computing
 
Ibm db2update2019 icp4 data
Ibm db2update2019   icp4 dataIbm db2update2019   icp4 data
Ibm db2update2019 icp4 data
 
Ibm messaging & collaboration roadmap 2013 (external)
Ibm messaging & collaboration roadmap 2013 (external)Ibm messaging & collaboration roadmap 2013 (external)
Ibm messaging & collaboration roadmap 2013 (external)
 

Plus de Mike Brannon

Search for Overview for SC Upstate SP users
Search for Overview for SC Upstate SP usersSearch for Overview for SC Upstate SP users
Search for Overview for SC Upstate SP users
Mike Brannon
 

Plus de Mike Brannon (12)

Microsoft Security Advice ISSA Slides.pptx
Microsoft Security Advice ISSA Slides.pptxMicrosoft Security Advice ISSA Slides.pptx
Microsoft Security Advice ISSA Slides.pptx
 
Secure Your Cloud Migration - Secureworld 2019 Charlotte
Secure Your Cloud Migration - Secureworld 2019 CharlotteSecure Your Cloud Migration - Secureworld 2019 Charlotte
Secure Your Cloud Migration - Secureworld 2019 Charlotte
 
Move Securely to the Microsoft Cloud
Move Securely to the Microsoft CloudMove Securely to the Microsoft Cloud
Move Securely to the Microsoft Cloud
 
BYOD - Mobility - Protection: security partnering with business
BYOD - Mobility - Protection: security partnering with businessBYOD - Mobility - Protection: security partnering with business
BYOD - Mobility - Protection: security partnering with business
 
Secure Your Mobile Content!
Secure Your Mobile Content!Secure Your Mobile Content!
Secure Your Mobile Content!
 
Secure mobile content SharePoint Best Practices Conference 2013
Secure mobile content   SharePoint Best Practices Conference 2013Secure mobile content   SharePoint Best Practices Conference 2013
Secure mobile content SharePoint Best Practices Conference 2013
 
SharePoint Best Practices Conference 2013
SharePoint Best Practices Conference 2013SharePoint Best Practices Conference 2013
SharePoint Best Practices Conference 2013
 
Search for Overview for SC Upstate SP users
Search for Overview for SC Upstate SP usersSearch for Overview for SC Upstate SP users
Search for Overview for SC Upstate SP users
 
NGC records management - SP2010 RM Features
NGC records management - SP2010 RM FeaturesNGC records management - SP2010 RM Features
NGC records management - SP2010 RM Features
 
Mobile Devices Securely Accessing SharePoint
Mobile Devices Securely Accessing SharePointMobile Devices Securely Accessing SharePoint
Mobile Devices Securely Accessing SharePoint
 
Smartphone security
Smartphone securitySmartphone security
Smartphone security
 
Find It With Share Point Search
Find It With Share Point SearchFind It With Share Point Search
Find It With Share Point Search
 

Dernier

+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
?#DUbAI#??##{{(☎️+971_581248768%)**%*]'#abortion pills for sale in dubai@
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Safe Software
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Safe Software
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
WSO2
 

Dernier (20)

Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
Six Myths about Ontologies: The Basics of Formal Ontology
Six Myths about Ontologies: The Basics of Formal OntologySix Myths about Ontologies: The Basics of Formal Ontology
Six Myths about Ontologies: The Basics of Formal Ontology
 
ICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesICT role in 21st century education and its challenges
ICT role in 21st century education and its challenges
 
Understanding the FAA Part 107 License ..
Understanding the FAA Part 107 License ..Understanding the FAA Part 107 License ..
Understanding the FAA Part 107 License ..
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024
 
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
 
WSO2's API Vision: Unifying Control, Empowering Developers
WSO2's API Vision: Unifying Control, Empowering DevelopersWSO2's API Vision: Unifying Control, Empowering Developers
WSO2's API Vision: Unifying Control, Empowering Developers
 
Vector Search -An Introduction in Oracle Database 23ai.pptx
Vector Search -An Introduction in Oracle Database 23ai.pptxVector Search -An Introduction in Oracle Database 23ai.pptx
Vector Search -An Introduction in Oracle Database 23ai.pptx
 
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
 
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdfRising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
 
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ..."I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 
[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
 
DBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor Presentation
 

Mobile Device Security - Responsible Not Repressive

  • 1. Responsible Not Restrictive Mike Brannon Dir. Infrastructure & Security, National Gypsum 1
  • 2. National Gypsum Company is a fully integrated building products manufacturer Headquartered in Charlotte, NC with mines and quarries, and manufacturing plants across North America 2
  • 3. National Gypsum and MobileIron Nov 2009 June 2012 (National Gypsum (M2) buys MobileIron) iPads sold by 0 >70 million Apple MobileIron 7 2300 customers … countries 2 32 … employees 39 320 3 MobileIron - Confidential 3
  • 4. National Gypsum Mobile Requirements Business users pick devices they want (not Blackberry) SECURE process to enable / allow BYOD phones, iPads ActiveSync and Juniper VPN connections DEVICE level security and respect for “employee data” – PIN/passcode, device / backup, encryption – NO jailbreaks, MDM and SW inventories Elected NOT to use most “mobile intel” – employee issues – Using last location / international warning message Next: PKI SCEP mgmt, app deployment coming, iOS domination 4
  • 5. Evolving Mobile Strategy FIRST: Email It’s all about email all the time NEXT: Personal tools Leverage the app store for personal tools • Sales/service, office, plant, engineers – DIVERSITY NOW: Connecting data Connect our data/processes with employees, partners, customers • NGC4ME is .NET custom web app – one-stop shop • SharePoint is private cloud/content manager/etc. 5
  • 6. Principles / Learning… Do not custom develop unless absolutely required – Leverage smart devices and off-the-shelf components – Stay away from super customized work – takes resources – Approach as “Systems Integrator” – assemble proven components Keep focused on USABLE solutions to business issues – “Voice of the Customer” as the priority guide! Remember technically simple solutions are better (Agile/Nimble) – Cannot assume that “best” will always be “best” Leverage existing technology components – Microsoft AD/PKI, Servers; Juniper VPN; .NET Development Security cannot just say NO – offer the secure option 6
  • 7. What we implemented ActiveSync email access – Exchange 2007/ISA then; – Now Exchange 2010 and Juniper/Junos Pulse – All devices “under management”; all users Juniper – Junos Pulse VPN access (iPad/iOS) – SharePoint and .NET web applications delivered (“NGC4ME”) -- SharePlus and Colligo Briefcase Field sales / customer svc / marketing deployment – Collection of apps (BrainShark/SharePlus/Concur) – Now working on custom app / deployment / one click (NGC4ME) Legal / security issues with some approaches – DropBox NOT permitted – Box.Com and SharePoint in use instead – Avoid “personal accounts” in favor of more “enterprise ready” answers 7
  • 8. High Level Architecture PKI Server, MobileIron HSM iPad NGC AD Servers MobileIron Enrollment iPhone, Juniper SSL VPN • Policy Checking Android MDM Configuration • WiFi, VPN, Certs/Apps Exchange CAS SharePoint / .NET Mailboxes Exchange CAS Sentry MI Sentry • Email is „User Driver” Juniper VPN as Proxy • AD Integrated SQL Databases SharePoint Portal/.NET • Windows Servers SQL • XML Interfaces M/F Mainframe 8
  • 9. App Challenges - Responses Challenge Response Beyond email, our employees SharePoint is open, web leverage shared content oriented content manager Apps deliver data into SharePoint Users save data into team sites, (Reports, Search-BCS) workflow and email ties “Personal Cloud” based upon MySites and user profiles Simple web forms SharePoint Lists – Mobile Safari OR Apps (see below) Surveys, pictures and easy Colligo, SharePlus, Filamente analysis (More complex!) and Docs2Go provide great tools 9
  • 10. Core philosophy – Responsible but not restrictive Vision: “Do the right thing for the right reason” (Security, risk & compliance – collaboration with the business) Security cannot just say NO … Must offer a secure option Business Need Options Proposed Response / Solution Easy-to-use cloud DropBox, iCloud, various Internal users: storage “personal” storage SharePoint MySites accounts and services External: Box.Com Full-fidelity Keynote conversion, Business account: presentations with personal Slideshare, BrainShark animations SlideShark 10
  • 11. Thank you 11

Notes de l'éditeur

  1. Late 2007 – Only corporate procured Blackberry allowed – BES for security and controlMove to “user choice” as the number of good choices multiplied iPhone (ATT Only) and Android / Win Mobile (Mostly Verizon) phones start replacing BlackberryNeeded a way to setup and enforce consistent policy across a varied fleet of devices! But how?2008 Audit finings!2009 project to improve security – MobileIron decision / deployment!
  2. Current requirements – Beyond “email on my phone” and now moving into “I need a mobile application”Biggest threat – lost or stolen / misused/abused devices – Data loss and unauthorized data accessEnrollment REQUIRED – Easy to do – But some controls to prevent casual, unmanaged connections PIN/Passcode Required - NOT Simple, minimum 6 characters/numbers, wipe after too many tries…Enforced device and backup data encryption – Jailbreaking not supported!!SW Inventory Required – Plans to deploy / manage SW more in near future!!
  3. Initially mobile users wanted access to their email – Continues to the BIG DRIVER across the board for mobile device connectionBlackberry served that purpose well – secure and managedMore user choices – Improved smart phones – move away from BlackberryNew smart phones – iPhone, Android – APP STORES – users choose devices and users access their own applicationsSales reps managing contacts, documents and their own information – STOP traveling with laptops all the timeiPad comes along and explosion of user app choices – Some reps practice real ‘laptop elimination” in favor of more mobile deviceExplosion of design and sales tools – architects, retail store personnel – Start trying to leverage INTERNAL data via APPS - SharePoint clients, Mobile SafariEngineers, Quality Control – Plant folks with iBooks, Kindle – SharePoint and web based appsHTML5 server content Juniper e=reverse web proxy“less” IE Specific Support requirements - .NET Apps – NGC4ME and SharePointUSER SIDE: Increasing numbers of devices per user – iPhone, iPad and a Laptop – Sometimes other devices – iPod Touch, mix and match device level!
  4. IT as a “System Integrator” – Limited resources and fast moving providers limit our interest / ability to DEEPLY CUSTOMIZEOpen up choice as much as possible WITHOUT compromising data / systems security too muchStay focused on delivering business user valueLeverage and integrate with EXISTING technology – Internal PKI – Juniper SSL VPN (Junos Pulse) -- .NET Development (HTML5) SQL and XML Integration
  5. Two Key Mobility Tools:MobileIron for Security / MDMJuniper Secure Access for authentication, access control, server protection – VERY Robust solution that covers far more than these mobile devices –Customer / Partner extranet, Associate VPN and/or basic intranet accessExchange Server 2010 email and related contentSharePoint 2007 data stored/managed; ECM / reports / simple apps.NET Web services and sites – Tight connections into IBM Mainframe transaction processing and hosted SAP financial systems(XML Gateway / data connections from Software AG tools)
  6. Link iOS to SharePoint contentLeverage rich SharePoint Apps in the App Store to access / edit / update LISTS, PICTURES/MEDIA“Personal Cloud” – Windows Laptop tied to MYSITES – App on iPad tied into Document Libraries
  7. Our core philosophy is provide for responsible, flexible secure use – without being too restrictiveMI Agent on device and system gives us structure around granting access – delivering configuration, content and security controlsUser benefits and business productivity more than offset the perceived costsDue to content management, e-discovery and related legal hold concerns we made a decision NOT to allow use of personal level accounts connected to DropBox (or other personal cloud services).Setup internal “managed cloud” via iOS Apps that access Sharepoint readily.Internal users with a significant need for external sharing leverage BOX.Net – Business account is centrally managed – subject legal holds, searches for e-Discovery Same for BrainShark