Device security guidance
Guidance for organisations on how to choose, configure and use devices securely.
Pages
Page 35 of 37
Action 3 - Understand additional costs and implications
A BYOD approach involves additional complexity and cost when designing or managing your networks, services, and devices. We describe some of these below.
Increased support costs
Security controls previously applied to corporately owned devices may now need applying to a variety of hardware and software combinations.
This will increase your support demand in several ways. For example:
- The need to support a greater number of device types
- Keeping multiple operating systems patched and up to date
- Extracting audit logs and performing monitoring on a diverse range of operating systems
- Responding to security incidents across a variety of devices and operating systems
As your BYOD implementation expands, ensure you have sufficient IT support and expertise to manage a growing range of devices and device platforms.
The associated cost of supporting a variety of devices and operating systems, which may change rapidly, should also be considered.
Device support can go beyond the software of the device to include the hardware and components. You should consider the stance you will take on the repair of devices if a BYOD breaks - will you leave this solely to the user, or will you provide a service to repair the device? If you choose to leave it to the user, how will you manage the risk of potential unauthorised access to corporate data by the repair service?
You may wish to wipe corporate data from a device before a user sends it for repair, but should have a plan for when this isn’t possible, as when the device’s battery is not chargeable.
You should have a process in place for handling these scenarios, including a clear statement on whether the user or an organisation administrator initiates the process.
Increased reliance on procedural controls
You might communicate your BYOD policy through employee training, user security procedures and education. If you do this, you will need to ensure that your staff understand their responsibilities when using their own devices for business.
This is important because people often approach security differently when using their own device. For example, staff may be happy to let family members use their own device, or provide credentials (including passwords) to a third party for maintenance or repair. You will be reliant on procedural controls where technical controls are unavailable, as is the case when you want to restrict device sharing.
You should also conduct regular audits of the business data stored on, or accessible from, personal devices – technical solutions can help with this. When staff leave your organisation or replace their device, you should ensure all business data is removed and credentials to access business systems are revoked.
Potential legal issues
From a legal perspective, the responsibility for protecting information rests with the data controller, not the device owner. As such, you should read the ICO’s BYOD Guidance and be aware of laws relating to your business data. In particular:
- The Data Protection Act (DPA), which states that employees must take measures against unauthorised or unlawful processing of personal data.
- The Employment Practices Code, which states that employees are entitled to a degree of privacy in the work environment.
- The General Data Protection Regulation (GDPR), which can have a number of consequences for organisations taking a BYOD approach.
In addition, consider how your organisation’s other obligations can be met if personal devices are being used as part of your business. Regulated industries, in particular, may face a number of additional obstacles to a successful BYOD implementation.
You may also need to consider how any commercial or partner agreements are affected by adopting BYOD. For example, there may be existing commercial agreements between organisations that restrict the running of business software or accessing business data on personally owned devices.
Good practices for BYOD
BYOD should be used for a limited set of defined tasks that are acceptable to your risk appetite. Anything outside of these defined tasks should be handled by corporately owned/fully managed models of working, instead.
Users should be explicitly informed and made aware of their obligations regarding how they access, manage, and use corporate data and resources, and how this may differ from their obligations when using corporately managed IT.
Similarly, organisations must understand their obligations to employees (the device owners), as well as their legal and corporate responsibilities. This should include ensuring that as little burden as possible is put on the users and as much is done via the technical controls you implement.
Getting this balance right - much like the balance between security and usability - is essential for all parties involved.
If for any reason an employee is unable to abide by your policies (for example, an inability to separate users on a device used for BYOD that is shared amongst family members), then BYOD access should not be permitted.
Protecting against data loss
Regardless of the BYOD approach chosen, we recommend that organisations do the following to protect the services and data being accessed:
-
Only present the minimum set of services and data required to BYOD users
This can be achieved by, for example, adjusting user permissions or service access policies. Where it is reasonable to do so, organisations should provide staff with a remote ‘view’ of information from their device, rather than allowing data to persist locally on their device. Doing so minimises the amount of data that can be easily accessed if their device is lost or stolen, as well as helping to prevent bulk data theft if the device is infected with malware.
Note that security solutions, such as encryption and container products, can be circumvented if malware is present on the device.
-
Employ strong user authentication methods
Your authentication approach may differ to that of other working practices. MFA should be enforced as a minimum, as devices will be connecting to cloud and other internet-based services. Some types of authentication credentials can become compromised, which is one of the reasons why the NCSC recommends using MFA.
Authentication measures should be designed with staff in mind, so that they are as usable as possible. Methods such as Single Sign On (SSO) and Passwordless are designed with this balance in mind. Standard corporate credentials, alongside MFA, can be used for access to services and data. See NCSC guidance on Multi-factor authentication for online services for more information.
-
Authenticate the device, if possible
Upon first use, your organisation will likely have to trust that the device connecting is legitimate, but for organisations with a low risk appetite, additional measures may be taken.
For example, initial connection of a personal device may only be allowed from a verified location, such as a segmented trusted network, on a corporate site. Further information on implementing effective authentication on devices is available in the section on Mobile Device Management.
Staff should be advised to use different passwords for unlocking the device and accessing corporate services and data.
Dependent on the approach taken by your organisation, it may be possible to generate or store authentication credentials within the secure environment available on many modern devices. This will help keep these safe if a device is compromised.
-
Employ risk-based authentication and access control, if this is possible
Risk based authentication makes ‘if-then’ decisions based on meta-identity data, such as device, location, and resource request. The service should constrain access if the risk associated with the request gets too high, automatically raise alerts, and use the meta-identity data to apply risk ratings to authentication and data access attempts.
If it is not possible to apply sufficient technical controls, organisations may want to create new user accounts that can only access a more limited subset of corporate data and services. It may also be possible to apply access control to your individual data repositories.
Access control policies should deny access from devices that do not comply with your policy, use legacy authentication protocols, or unsupported client applications. Further authentication assurance may also be required for devices in untrusted or unexpected network locations.
-
Monitor the service and data being accessed as effectively as possible
For example, you should record:
- event times
- source IP addresses
- device/user agents
- failed and successful authentication, authorisation, resource requests
- object access
Alert on unsanctioned activity (for example, non-BYOD users requesting access from a BYOD device).
According to the ICO, under GDPR, MAC addresses and IP addresses can be classed as personal identifying information. Consent from users will be required for monitoring, if these are to be collected and stored.
-
Assess, understand, and manage the risks
Business risk owners should be well informed about risks associated with BYOD and make careful decisions about what data and services they wish to expose. The trust that you would have in a corporately managed device will not be the same as that which you give to a personal device. Assume that you cannot fully trust the device used (although you should still use available controls to minimise risk) and place the focus on securing your data and services.
-
Select an approach that is compatible with the majority of supported devices that staff already own.
Organisations will have to decide whether to allow non-supported devices to connect to their services and data in the context of the security risks. Approaching this with a solution that is accessible to as many members of staff as possible will be most beneficial.
Have a defined minimum set of security standards for consuming enterprise data.
-
Have processes and procedures in place
These should clearly state what your organisation expects staff to do, and how to do it, for a given situation. This should include the minimum expected security standards required for a device to be marked as ‘compliant’.
These can be used to inform your access control policies and practices, such as: using PIN access for corporate applications on personal devices; the application specific VPN configuration parameters; and the mitigations you may choose to put in place to selectively lock the device or wipe enterprise data in the event of theft or loss (if possible with the controls you decide).
Our Device Security Guidance will help you to determine the minimum security standards you should be looking to achieve.