Professional Documents
Culture Documents
Lee Neely
CISSP, MSP ISSO
Lawrence Livermore National Laboratory, P. O. Box 808, Livermore, CA 94551 This work performed under the auspices of the U.S. Department of Energy by Lawrence Livermore National Laboratory under Contract DE-AC52-07NA27344
LLNL-PRES-412835
Device Focus
BlackBerry iPhone
Corporate device Many security features Business applications new app store released Optimized for centralized management Runs device specific software CDMA/GSM/Wi-Fi Verizon/AT&T/Sprint/etc.
Lawrence Livermore National Laboratory
LLNL-PRES-412835
Consumer device Nominal security Lots of new and cool apps Optimized for individual management Runs a version of Mac OS X GSM/Wi-Fi AT&T service only
4
iPhone
Configure built-in VPN to access corporate network (Configuration can be sent to device) Device accesses existing services user configures
ActiveSync if Exchange POP/IMAP services if using Web Applications
Time
Per device ten minutes Pre-setup configuration setting file (optional)
iPhone
Create configuration w/iPhone Configuration Utility (ICU) and deploy to secure web server in DMZ Edit iPhone policies in Exchange (optional) Install and configure ActiveSync in DMZ User finalizes configuration (Username/Passwords) Time
Per device two minutes Pre-setup configuration, ActiveSync, etc.
iPhone
Managed when it can reach ActiveSync (VPN, DMZ, or hole in firewall.) User content updates only when it can reach ActiveSync DMZ solves Access to corporate applications when VPN connected. Settings can be removed deletion removes data
Security Features
Function
Secure Contents Security Configuration store Communication Model Live Policy Updates Wipe Inactivity Lock Remote Lock Sync email/calendar/notes Encrypted communications Web Browser functionality Access to internal Net
BlackBerry
Content Encryption (memory card separate) BES Device connects to RIM then to BES, BES is corporate gateway. BES provides continuous connection tight coupling Yes, Remote or manual - BES initiates has DOD spec wipe. Memory card separate BES configures Yes, BES initiates Via BES Certificate Exchange PKI protects end-toend MDS provides gateway, some applications work, BES admin must configure BES /MDS
iPhone
Need application e.g.: Sybase iAnywhere Mobile Office Suite Exchange Policies/iPhone Configuration Utility (ICU) Device connects to ActiveSync over VPN and/or Internet. VPN for corporate apps When ActiveSync is reachable, over VPN or Internet loosely coupled Yes, remote must be connected to ActiveSync, manual has erase option. Policy can be pushed from ActiveSync N/A Via ActiveSync ActiveSync server connected via SSL. IPSec VPN to corporate network. Business Applications work, need VPN or gateway, device configured Need VPN or gateway device configured
10
BlackBerry
BES pushes to device Works- with right SW, and exportable cert. WEP, WPA personal & enterprise, WPA2 personal & enterprise IPSec VPN some models works with Wi-Fi, not required with BES/MDS Remove Battery BES/MDS (Centralized) BES or Desktop Manager Business user Many business focus. Can control tightly.
iPhone
Policy can be pushed from ActiveSync Need application e.g.: Sybase iAnyware Mobile Office Suite WEP, WPA personal & enterprise, WPA2 personal & enterprise, 802.1X EAP, PEAP & LEAP Cisco IPSec, L2TP/IPSec, PPTP Only option is airplane mode VPN (Decentralized) or ICU configuration iTunes SW update Consumer Many consumer focused. Issue of personally licensed software and introduction of Malware No limit
VPN L/Q Building Startup Device Management and Software Updates Target Audience Applications
Application restrictions
11
Conclusion
BlackBerry
Moderate setup Moderate entry fee Strongly managed Always on synchronization Structured device software updates BES or Desktop Software can restore configuration Limited application compatibility you may need a laptop for full functionality Content protection or S/MIME support -native
Lawrence Livermore National Laboratory
LLNL-PRES-412835
iPhone
Quick Startup Low entry fee Loosely managed Syncs when ActiveSync reachable Immediate device software updates iTunes can restore configuration (from desktop) High degree of application compatibility are able to run most business apps/webmail. Content protection or S/MIME support additional application.
12
Questions?
13