<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>hand-held Archives -</title>
	<atom:link href="https://zymitry.com/tag/hand-held/feed/" rel="self" type="application/rss+xml" />
	<link>https://zymitry.com/tag/hand-held/</link>
	<description>Tech &#38; Other Stuff</description>
	<lastBuildDate>Fri, 26 Jan 2018 00:24:02 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0</generator>

<image>
	<url>https://i0.wp.com/zymitry.com/wp-content/uploads/2016/11/favicon.png?fit=32%2C32&#038;ssl=1</url>
	<title>hand-held Archives -</title>
	<link>https://zymitry.com/tag/hand-held/</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">120106411</site>	<item>
		<title>Security Policy Template for Hand-Held Devices</title>
		<link>https://zymitry.com/security-policy-hand-held-devices/</link>
					<comments>https://zymitry.com/security-policy-hand-held-devices/#respond</comments>
		
		<dc:creator><![CDATA[Greg Palmer]]></dc:creator>
		<pubDate>Fri, 26 Jan 2018 00:23:40 +0000</pubDate>
				<category><![CDATA[Information Security Compliance]]></category>
		<category><![CDATA[device]]></category>
		<category><![CDATA[hand-held]]></category>
		<category><![CDATA[policies]]></category>
		<category><![CDATA[policy]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[template]]></category>
		<guid isPermaLink="false">https://zymitry.com/?p=923</guid>

					<description><![CDATA[<p>Hand-Held Device use has become common place in today&#8217;s business environment to include company owned assets, and personal &#8220;Bring Your Own Device&#8221; (BYOD)&#8217;s. Security of Hand Held Devices normally spans over many of the other standard domains making it practical to treat them as a separate domain.. The SANS Reading Room article; Security Policy for… <span class="read-more"><a href="https://zymitry.com/security-policy-hand-held-devices/">Read More: Security Policy Template for Hand-Held Devices &#187;</a></span></p>
<p>The post <a href="https://zymitry.com/security-policy-hand-held-devices/">Security Policy Template for Hand-Held Devices</a> appeared first on <a href="https://zymitry.com"></a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Hand-Held Device use has become common place in today&#8217;s business environment to include company owned assets, and personal &#8220;Bring Your Own Device&#8221; (<a href="https://zymitry.com/byod-policies-practices/" target="_blank" rel="noopener">BYOD</a>)&#8217;s. Security of Hand Held Devices normally spans over many of the other standard domains making it practical to treat them as a separate domain..</p>
<p>The SANS Reading Room article; Security Policy for the use of handheld devices in corporate environments, provides a security <a href="https://zymitry.com/security-policies-standards-procedures/" target="_blank" rel="noopener">policy</a> template for Governing the use of hand-held devices in a corporate environment. Standard template elements are as follows:</p>
<ul>
<li>Introduction</li>
<li>Purpose</li>
<li>Scope of application and obligation</li>
<li>Roles and Responsibilities</li>
<li>Target Readership</li>
<li>How to use the policy template</li>
<li>Definitions</li>
<li>References</li>
</ul>
<p>The actual security policy contains the following elements:</p>
<ul>
<li>General policy requirements which discuss a wide range of elements to include roles and responsibilities of users, inventory of mobile devices, authorized and forbidden services, and user awareness training.</li>
<li>Physical security. This policy includes, physical security as it relates to theft or loss of a mobile device, device safety, password requirements, ownership, remote blocking and wiping, availability and business continuity, and camera use.</li>
<li>Operating System (OS) security. Items covered include firmware and OS update and patching, hardening, signed and unsigned application use, firewalls and anti-virus, and defining a security model for the device itself.</li>
<li>Personal Area Network (PAN) security. Items covered here include, the use of Bluetooth, PINS and pairing, Bluetooth device security, file transfer over PAN, audits, and unauthorized use.</li>
<li>Data security. A few items covered here include, information classification, restrictions, data security as it relates <a href="https://zymitry.com/ethics-related-collection-information/" target="_blank" rel="noopener">handling information</a>, and encryption.</li>
<li>Corporate network access security. Some items listed are. Access control to the network, remote access to corporate resources, internal access to resources, and wireless support.</li>
<li>Over-the-air provisioning security. This policy covers device management, provision security, and communications security</li>
<li>Internet security. Includes acceptable use, general email security, and attachment restrictions,</li>
<li>Forbidden services</li>
<li>Unauthorized actions</li>
</ul>
<p>Overall, the template generally falls in line with other commonly used policy <a href="https://zymitry.com/primary-advantages-cobit-iso-27000-nist/" target="_blank" rel="noopener">frameworks</a>. It covers all the general elements with the exception of legal or industry general requirements.</p>
<p>References</p>
<p>Guerin, N., &amp; Wanner, R. (2008, May 29). <em>Security Policy for the use of handheld devices in corporate environments. </em>Retrieved September 19, 2017, from <a href="https://www.sans.org/reading-room/whitepapers/pda/security-policy-handheld-devices-corporate-environments-32823" target="_blank" rel="noopener">https://www.sans.org/reading-room/whitepapers/pda/security-policy-handheld-devices-corporate-environments-32823</a>.</p>
<p>Johnson, R. (2015). <em>Security Policies and Implementation Issues (2nd ed</em>.). Burlington, MA: Jones &amp; Bartlett Learning.</p>
<p>The post <a href="https://zymitry.com/security-policy-hand-held-devices/">Security Policy Template for Hand-Held Devices</a> appeared first on <a href="https://zymitry.com"></a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://zymitry.com/security-policy-hand-held-devices/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">923</post-id>	</item>
	</channel>
</rss>
