[論文レビュー] Bring-Your-Own-Device (BYOD): An Evaluation of Associated Risks to Corporate Information Security
この論文は、企業環境における持ち込み端末(BYOD)ポリシーに関連するサイバー危険を評価し、不十分なセキュリティ制御のため、データ損失が主な脅威であると特定している。専門家の意見とリスク評価を用いて、管理されていない個人用端末からの脆弱性を強調し、生産性と情報セキュリティの両立を図るための緩和戦略を提案する。
This study evaluates the cyber-risks to Business Information Assets posed by the adoption of Bring-Your-Own-Device (BYOD) to the workplace. BYOD is an emerging trend where employees bring and use personal computing devices on the companys network to access applications and sensitive data like emails, calendar and scheduling applications, documents, etc. Employees are captivated by BYOD because they can have access to private items as well as perform certain job functions while being unrestricted to their desks. This is however usually done on the blind side of management or the system administrator; a situation that tends to expose vital and sensitive corporate information to various threats like unwanted network traffic, unknown applications, malwares, and viruses. Expert opinions were elicited in this exploratory study. The study evaluated the characteristics of BYOD, assessed associated risks, threats and vulnerabilities. The findings indicate that little or no security measures were instituted to mitigate risks associated with BYOD. Though, profound benefits abound with BYOD adoption, they could be eroded by security threats and costs of mitigation in curing breaches. The most significant risk was found to be Data Loss which was in consonance with similar studies on Smartphone security risks. Some mitigation measures are then recommended.
研究の動機と目的
- 従業員が企業ネットワークで個人端末を使用することによって生じるリスクを評価すること。
- 企業におけるBYODの導入に関連する主な脅威および脆弱性を特定すること。
- BYOD関連のリスクに対し、既存のセキュリティ制御(あるいはその欠如)を評価すること。
- BYOD環境におけるサイバー脅威への露出を低減するための実用的な緩和戦略を提案すること。
提案手法
- 情報セキュリティ専門家の意見に基づく探索的調査を実施した。
- BYODの特性を分析し、企業ネットワークへの統合を理解すること。
- マルウェア、不正なアプリケーション、個人端末からのネットワーク侵入などの脅威を評価すること。
- デバイス管理の欠如、アクセス制御の弱さ、暗号化の不十分さと関連する脆弱性を同定すること。
- 影響度と発生可能性に基づいて脅威をランク付けするための定性的リスク評価を実施した。
- 同定されたリスクと専門家のコンSENSUSに基づき、セキュリティ緩和策を提案した。
実験結果
リサーチクエスチョン
- RQ1企業環境におけるBYOD導入に関連する主なサイバー危険は何か?
- RQ2管理されていない個人用端末は、企業の情報資産にどのように脆弱性をもたらすか?
- RQ3BYOD状況におけるデータ機密性および整合性の分野で、最も深刻な脅威は何か?
- RQ4現在のセキュリティポリシーは、BYOD関連のリスクをどの程度効果的に緩和しているか?
- RQ5BYOD展開におけるデータ損失リスクを効果的に低減するためのセキュリティ制御は何か?
主な発見
- データ損失は、スマートフォンセキュリティ研究の結果とも一致するBYOD環境における最も深刻なリスクであると特定された。
- BYOD導入に関連するリスクを緩和するために、ほとんどまたはまったくセキュリティ措置が講じられていないことが判明した。
- 従業員はしばしば管理のない状態で個人端末を使用しており、マルウェアや不正アクセスへの露出が増加している。
- 中央集権的なデバイスマネジメントや暗号化の欠如は、機密データの不正持ち出しの可能性を高めている。
- BYODの利点は、セキュリティ侵害や是正作業のコストに上回られる可能性がある。
- 推奨される緩和戦略には、モバイルデバイスマネジメント(MDM)、データ暗号化、およびユーザー意識向上トレーニングが含まれる。
より良い研究を、今すぐ始めましょう
論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。
クレジットカード登録不要
このレビューはAIが作成し、人間の編集者が確認しました。