BYOD Security
Accommodate personal devices on your network, without compromising security.
Learn more about ForeScout solutions by downloading the brochure. Download »
Control who and what is accessing your network with CounterACT.
View the datasheet »
Frost&Sullivan assessment : NAC Global Technology
Innovation Award 2012 Read now »
Computer Technology Review CounterACT Receives Editor's Choice Read now »
Enabling people to access corporate network resources where, how and when needed without compromising security. Download the overview »
Accommodate personal devices on your network, without compromising security.
Users want to use their personal mobile devices to access corporate resources and data. Managers want productivity gains. This consumerization of IT—also known as Bring-Your-Own-Device or BYOD—represents a daunting security challenge. How can you accommodate employee and guest requests to use their smartphones, netbooks and tablets while mitigating security risks?
ForeScout CounterACT helps you enable BYOD by giving you real-time visibility of personal devices on your network, and allowing you to readily enforce guest network and access restrictions based on user and device policy.
ForeScout Mobile augments ForeScout CounterACT and provides additional visibility and management control over smartphones and tablet devices.
The Challenge
Increasingly, employees are bringing their personal devices into the office and expecting to connect them to the enterprise network and/or the Internet. In July 2011, IDC released a study indicating that 40.7% of devices used by information workers to access business applications are ones they own themselves, including laptops, smartphones, and tablets such as Apple’s iPad. That was a 10-point jump from the prior year’s study.1
Perhaps more concerning, this trend is happening faster than IT managers realize. When IDC surveyed IT managers about the number of consumer devices on their networks, they underestimated the number by 50%.
Consumer devices accessing corporate networks pose numerous security challenges. IT managers need to find a way to secure corporate data on the devices, protect the corporate network from infection by malware that may be present on the devices, and control the level of access the devices have to the corporate network.
The initial response of many IT organizations was to ban all consumer devices from their networks. But IT organizations are increasingly seeing that this is not a sustainable strategy. According to Gartner:
“Consumerization is an unstoppable trend, and most organizations need to demonstrate flexibility and allow employees to use their personal devices for work. But, they also need to establish limits and not permit every device, every operating system and every configuration. Although approaches such as server-based computing and virtualization will also be used to deal with consumerization, NAC provides the flexibility that enterprises need in a BYOD environment, while providing the controls that enable network and security managers to retain control over the network.”2
For a more extensive analysis of the risks presented by BYOD, read this whitepaper by well-known security analyst Mike Rothman and this whitepaper by the SANS Institute.
ForeScout’s Solution
While mobile device management (MDM) solutions are strong for provisioning, managing settings on and sandboxing smartphones, they do not provide granular control over network access, nor do they work on personal laptop computers. For a comprehensive solution, you need to be able to control the network layer directly as well.
ForeScout CounterACT is an automated network security platform that gives IT security managers an easy way to reduce the risks associated with BYOD. ForeScout CounterACT provides real-time visibility of personal devices on your network, limits the network access of those devices, and prevents those devices from spreading malware onto your network.
Step One – Visibility
Gartner estimates that the typical enterprise is aware of only 80% of the devices that are active on its network.2 ForeScout CounterACT shows in real-time all devices on your network, including devices that you don’t own. ForeScout CounterACT categorizes devices by type—Windows, Mac, Linux, Apple iOS, Android, Blackberry, printers, etc. ForeScout CounterACT also categorizes devices by ownership—corporate devices vs. personal devices. For more information on ForeScout CounterACT’s visibility features, see here.
ForeScout CounterACT Mobile Security Module provides even greater visibility by providing deep inspection of Android and iOS devices including information about the hardware, software, and configuration of these devices.
Step Two – Policy Enforcement
Since all endpoints are identified and profiled, ForeScout CounterACT lets you enforce whatever BYOD policies you wish for your organization. You may choose to prohibit consumer devices on your network. Or you may wish to allow some (or all) consumer devices onto your network. Or you might want to choose a middle ground, for example: allow consumer devices onto you network, but limit the resources they can connect to. Regardless of your policy, ForeScout lets you enforce these policies automatically. ForeScout CounterACT enforces policies for all devices—devices you own, and devices you don’t own—from a single centralized management console.
Step Three – Tier the Mobile Security Service
For BYOD, organizations can’t solely consider employing MDM solutions enterprise wide – it is costly, often is viewed by employees as a more intrusive application, only applies to smartphones and tablets, and is not suitable for guest management. The more efficient and cost-effective approach is to offer different levels of mobile security to different classes of users, devices and required application access by employing ForeScout CounterACT, ForeScout Mobile Security Module and ForeScout Mobile MDM Module.
Note 1: http://www.cio.com.au/article/393246/idc_it_hasn_t_grasped_consumerization_trend/
Note 2: “Strategic Road Map for Network Access Control”, Gartner, 11 October 2011, Lawrence Orans and John Pescatore.
ForeScout CounterACT and ForeScout Mobile Security Module help IT security managers solve the BYOD problem:
- ForeScout CounterACT limits guest access, preventing them from accessing sensitive resources
- ForeScout CounterACT ensures that guest devices meet your security policies while they are connected to your network
- ForeScout CounterACT continuously monitors guest systems to ensure that they do not attack your network.
This video demonstrates the use of ForeScout CounterACT to identify mobile handheld devices on the network and offer role-based access. Corporate devices are provided full access automatically while guests can be registered via SMS for 100% user verification.
Mobile DevicesForeScout CounterACT identifies handheld devices on your network – iPhone, iPad, Android, Windows Mobile, Blackberry, Nokia Symbian.
Mobile Device PropertiesForesScout mobile shows you an inventory of mobile device properties on your network.
Mobile Application InventoryForeScout Mobile provides a real-time inventory of all mobile apps on your network