Skip to main content
QUICK REVIEW

[论文解读] Investigating Information Security Risks of Mobile Device Use within Organizations

William Bradley Glisson, Tim Storer|arXiv (Cornell University)|Aug 21, 2013
Privacy, Security, and Data Protection参考文献 10被引用 9
一句话总结

本实证研究通过分析一家全球财富500强公司返还的32台员工移动设备,调查企业环境中移动设备的安全风险。研究发现存在重大政策违规和数据泄露风险,包括未加密数据和未经授权的应用程序,为未来组织环境中移动安全研究提供了基础性见解。

ABSTRACT

Mobile devices, such as phones, tablets and laptops, expose businesses and governments to a multitude of information security risks. While Information Systems research has focused on the security and privacy aspects from the end-user perspective regarding mobile devices, very little research has been conducted within corporate environments. In this work, thirty-two mobile devices were returned by employees in a global Fortune 500 company. In the empirical analysis, a number of significant security risks were uncovered which may have led to leakage of valuable intellectual property or exposed the organization to future legal conflicts. The research contribution is an initial empirical report highlighting examples of corporate policy breaches by users along with providing a foundation for future research on the security risks of the pervasive presence of mobile devices in corporate environments.

研究动机与目标

  • 调查企业环境中移动设备使用相关的信息安全风险。
  • 识别员工配发移动设备中具体的企业政策违规情况。
  • 发现可能导致数据泄露或法律风险的技术与行为漏洞。
  • 为未来组织中移动安全研究提供初步实证基础。

提出的方法

  • 对一家全球财富500强公司员工返还的32台移动设备进行实证分析。
  • 收集并检查设备数据,包括存储文件、安装的应用程序及配置设置。
  • 通过设备内容的取证检查评估对企业的安全政策合规性。
  • 基于敏感数据的存在、弱加密和未经授权软件的发现,识别并分类安全风险。
  • 使用定性与描述性分析方法记录观察到的政策违规和风险模式。

实验结果

研究问题

  • RQ1在企业环境中的员工移动设备中存在哪些类型的信息安全风险?
  • RQ2员工移动设备在多大程度上违反了既定的企业安全政策?
  • RQ3在分析的设备中发现了哪些具体的数据暴露或漏洞?
  • RQ4用户行为和设备配置在多大程度上加剧了组织的安全风险?

主要发现

  • 32台移动设备显示出显著的安全风险,包括在设备上存储的未加密敏感数据。
  • 许多设备含有违反企业安全政策的未经授权应用程序。
  • 在员工设备的非安全位置发现了有价值的技术知识产权,增加了泄露风险。
  • 多个设备表现出弱加密或无加密,使数据面临潜在泄露风险。
  • 研究发现了可能导致组织面临法律或监管冲突的政策违规证据。
  • 研究结果凸显了企业环境中移动设备使用普遍且常未受管理的安全风险。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。