Network Security & Hardware - eWeek

Network Security & Hardware: Five iPhone Security Tips for IT Departments


Share

With the popularity of Apples iPhone on the market, IT managers need to think about how to secure the iPhone when it comes into their networks. Smart policy is the name of the game. With that in mind, The Center for Internet Security recently released a security benchmark for the iPhone to help both administrators and end-users better secure data stored on the device.

In a document entitled the "CIS Security Configuration Benchmark for Apple iPhone," CIS included 20 recommendations on subjects such as system settings and instructions on creating strong passwords. The advice, which applies to those who have not yet upgraded to iPhone 3GS, was created based on input from a diverse set of experts from the worlds of IT security, software developers and other fields.

eWEEK has selected some of the recommendations and included how to set your iPhone to be more secure.
 
  • Five iPhone Security Tips for IT Departments
    By Brian Prince
  • Update Firmware to the Current Version
    iPhones ship with the version of the firmware that was current at the time of manufacturing, but updates may have been released since then. Firmware updates include not only new features and bug fixes, but security fixes as well.
  • Set a Passcode
    Users should configure the iPhone to require a passcode before it can be used. This can help make it more difficult for an unauthorized user to access any data on the device if it is lost or stolen.
  • Destroy Data if the Wrong Password Is Entered
    Users should consider setting their phone to erase data stored on the device after an excessive number of passcode failures. CIS recommends it be set to erase after 10 failed access attempts.
  • Passcodes in the ICU
    Users of the iPhone Configuration Utility (version 1.1.043) can do a number of things to ensure password strength, including requiring a mix of numbers and letters and setting a minimum passcode length.
  • Forgetting Wi-Fi Networks
    A trusted but unauthenticated network can be spoofed and automatically joined if the phone isnt set to forget the network after it was last used. According to CIS, if such a network has a common SSID, such as "default" or "linksys", it is probable the iPhone will encounter an untrusted instance of a same-named Wi-Fi network and automatically join it.
xڽZ[s۸~~d_Bvw7GҎ& HBb`P(n[$p Nd!뒱 i8lEh! g6!_!Dsig4']LsJ.,/NȈ fgA*^KkI0*_+{ܰxdVd2o^M$I"-Pm8*y515.,Sh f2V͖SP1;T:[DPz;kYaM1dɥq&}uܔBA=8by Ȱ 1WHD:&圩G0YM_GG^zSHH֩ӹK7mϩM}-_^У=jLןi6dpR3S41+Yyz +<@-y\bťSݞ!ԀE,"(5n TGF#`1t\+t&q`-ja#=k\U]|9:0oOp̯VzT-RyGp[f=PZEޒs6cHp|[Ij]&@8z$*{XU4dIV_C\SUNx>‘'wh,iVDz_L4& K|3;-ZqY=MdK9[Mt!c搘N|j8B=)iF7&vexLV'OJOfODZiJ2tl2ǬiU߀}SCv%aಜtug,xUO3/yL>grVWs<3cUus <}ܟܩypZ9 zO\ CE@v=<l0زM IbLm=%q5:rGϗplƯ-էF|B@Ln#'g5']&~3l۾aU҇ZsQ X+fu#P#J5sF`4zuXoթiP#IU=e]}22<ش: L1\| UPz>彲u;2^eu 2V"$`%R~0arFlv,bGV6o+7 6 G?D\=fL{MJz‰ ؠ T+?Z)KFOQpsѰW6_02HJ~%"hEM]Xdh5_a~bD+E{lNp#gLNfy7nq2a/_k?I>'",,fVDlY1g"YHz~u>Zɢ+}1'G3 'QDp tp I>S E!LY3=t"E&c2\s4^b1^J@:=&)KQhɕB#0Bt<>*lݱX |4aOzHD5.m9eD`x8RWf8{B#CD|tyl;z6#a3J@95'Ы5jG)\ꖇvY6U1{3v!V.5K$ IG^+3gDA/8*4n=ax^('XXcV  p[M5@Asy{3p/O_<&sdHcޑ+?.[.ryBr%vZ2.g_n#<ӓϟnޜ``d2wy\{,xs7l>]NgԖقT5 dc7Ec;Ox><=p !K߼4P5f!H>ߚߕa:ˑ4Z[Iv1wG%٧֩yVKYWX{(TS-z,?/ ʹewݙ,lUq ᒳ |.ovԨjY-