NSA wants bulletproof smartphone, tablet security
Network World - NATIONAL HARBOR, Md. -- The National Security Agency, America's high-tech spy agency which also plays a key role in approving hardware and software for use by the Department of Defense, wants to be able to outfit military personnel with commercial smartphones and tablets -- but based on a NSA security design.
The forces in the Department of Defense, including the U.S. Army and Air Force, today are piloting several different commercially available smartphones and tablets which the NSA is working to harden and secure, said Debora Plunkett, director of the NSA's information assurance directorate, speaking at the Gartner Security and Risk Management Summit 2011 here today. "It's not our intention to rely on any one platform," she said. The goal is to have perhaps four main devices, plus a couple of infrastructure support services, and let U.S. forces pick the one they like best, she said.
MORE ON SMARTPHONE SECURITY: Military wants full disk encryption for iPhone, Android smartphones
Finding a way to bring commercially available smartphones and tablets into the classified security environment is "our No. 1 challenge today," Plunkett said.
Right now, commercial smartphones and tablets are seen as carrying considerable risks from a national-security perspective, but the NSA is working to figure out how to add its own security to compensate for the risks.
"We are not saying there are no vulnerabilities in COTS [commercial off-the-shelf] products," Plunkett said. "The intention is to be able to layer the commercial products and alleviate and obviate the vulnerabilities."
For the NSA, it's all adding up to an evolving concept of "'good enough' security," Plunkett said, based on the idea that there are situations where information is highly "perishable" and retained only in minutes as compared with days or years, and that it's worthwhile taking the risk to use COTS products that themselves may be regarded as more perishable as well.
Certainly, though, for many of the more traditional NSA strategists who advocated the agency build network equipment and security products itself as was the practice in the past, "it's almost blasphemy," she added. Going to commercial products takes "a lot of control out of your hands."
NSA firmed up its mobility strategy last August, Plunkett said, and there are now several pilot tests in the armed forces of many of the leading smartphones and tablets. The goal is to find ones that can be approved, with specialized NSA security controls, for analysis and network use all around the world.
In its future secure mobile capability, now referred to as the "Mobile Virtual Network Operator," the NSA wants to be able to establish a way that sensitive content can be provided to the military and intelligence in a way that roughly emulates what Amazon does with Kindle, Plunkett said.


- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- The Essential Guide to Choosing a Web Analytics and Online Marketing Solution
- Today's customers have information at their fingertips and can dictate a new set of terms in the dynamic relationship between buyers and sellers....
- Plugging Information Leaks
- Unlike traditional data leak prevention solutions, which work at the network or desktop level, Attachmate Luminet software monitors end-user activity at the application...
- Shine a Light on Insider Abuse
- This solution brief describes the four technical challenges you face and tells you how Luminet can help you overcome them.
- Threats from Within Your Government Agency
- This solution brief tells how Attachmate Luminet fraud management software can help government agencies and departments get ahead of the fraud curve-by providing...
- Meeting the PCI-DSS Compliance Challenge
- This solution brief describes the four technical challenges you face and tells you how Luminet can help you overcome them. All Government/Industries White Papers
- Distributed Database Security with Real-time Monitoring
- View this demo and learn how IBM InfoSphere Guardium database activity monitoring can help protect your sensitive data in distributed DBMS environments with...
- InfoSphere Warehouse Packs Demo
- These flash modules make warehousing more tangible and relevant to business users through detailed explanations of the InfoSphere Warehouse Packs.
- Delivery Management -- Extending Lifecycle Management
- Date: Wednesday, June 20, 2012, 1:00 PM EDT
Siloed organizations continue doing the wrong things and doing things wrong, leading to increased costs,... - Leverage automation today to reduce IT complexity
- Date: Tuesday, June 5, 2012, 2:00 PM EDT
Whether your B2B complexity is caused by multiple technologies due to M&A, business or application specific... - Redefine Expectations in the Data Center
- Need to do more with less? Watch this video to learn how HP ProLiant Gen8 servers can help your business deploy servers three... All Government/Industries Webcasts