Gartner: iPods, other small storage devices pose security risk
Companies should consider banning them
IDG News Service - The iPod may be popular, but it also poses such a major security risk for businesses that enterprises should seriously consider banning it and other portable storage devices, according to a study by research firm Gartner Inc.
The devices, using a Universal Serial Bus (USB) or FireWire (IEEE 1394), are risky because they could be used to introduce malicious code into a corporate network or steal corporate data, the Stamford, Conn.-based research company said in its report, "How to Tackle the Threat From Portable Storage Devices."
The report, published Friday, pointed to a variety of devices, including pocket-size portable FireWire hard drives like those from LaCie Group SA or Toshiba Corp., or USB hard drives or key-chain drives such as the DiskOnKey from M-Systems Flash Disk Pioneers Ltd. Gartner also named disk-based MP3 players, like Apple Computer Inc.'s iPod, as a security risk, as well as digital cameras with smart media cards, memory sticks and compact flash.
Gartner advised companies to forbid employees and external contractors who have direct access to corporate networks from using these privately owned devices with corporate PCs. Companies should also consider a "desktop lockdown policy," disabling universal plug-and-play functions after installing desired drivers, to permit the use of only authorized devices.
The report conceded that the devices themselves can be quite useful within corporations, making it "unpractical and counterproductive" to introduce an outright ban.
Companies should take a multipronged approach to portable storage devices, Gartner said, including using personal firewalls to limit what can be done on USB ports. The use of products for selectively controlling ports and encrypting data should also be considered, the company said.
In addition, digital rights management technology should be used by enterprises that want to protect intellectual property, Gartner said.


- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Driving Secure Enterprise File Sharing and Syncing in the Enterprise
- GroupLogic's new activEcho is the industry's only secure Enterprise File Sharing and Synching solution that balances the need for simplicity for the end...
- The Enterprise File Sharing Option
- Enterprises and IT departments need to address several critical security issues when considering file sharing and syncing products. Many of today's solutions do...
- Security Strategies to Virtualizing Internet-Facing Applications
- The IT organization at Intel has set a goal to transition their enterprise to a private cloud for their Office and Enterprise applications....
- Cloud Security Planning Guide
- Cloud security considerations span protecting hardware and platform technologies in the data center to enabling regulatory compliance and defending cloud access through different...
- Cloud Security Vendor Round Table
- This vendor round table guide will help you to evaluate different cloud technology vendors and service providers based on a series of questions... All Security White Papers
- Live Webcast
Data Privacy and Protection in Production Environments: New Research from Ponemon Institute - Date: Wednesday, June 13, 2012, 1:00 PM EDT / 10:00 AM PDT
In a recent study conducted by Ponemon Institute, fifty-five percent of respondents... - Data Privacy and Protection in Production Environments: New Research from Ponemon Institute
- Date: Wednesday, June 13, 2012, 1:00 PM EDT / 10:00 AM PDT
In a recent study conducted by Ponemon Institute, fifty-five percent of respondents... - Security Certifications 101 - BlackBerry and all those acronyms what do they mean and why they matter?
- FIPS, Common Criteria, CAPS, AISEP, NFC, NIST, Fraunhofer SIT, CESG, DSD - these are just some of the government and industry certifications which...
- BlackBerry PlayBook OS 2.0 Security Overview
- The presentation provides an overview of BlackBerry PlayBook OS 2.0 security capabilities and features, including: BlackBerry® Balance™ technology, BlackBerry® Bridge, data-at-rest protection, and...
- BlackBerry NFC Security Overview
- The presentation on NFC security will provide an overview of the security protections built into the BlackBerry platform to protect users, application developers...
- Playing Defense: Staying on Top of Your Disaster Recovery Game
- When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing... All Security Webcasts