BYOD Security
Accommodate personal devices on your network, without compromising security.
SANS Critical Security Controls - See how NAC closes gaps.
Download »
EMA analyst report on assuring network access control (NAC) success. Download »
IDC analyst report on architecting a mobile security/BYOD strategy. Download »
Control who and what is accessing your network with CounterACT.
View the datasheet »
Learn more about ForeScout solutions by downloading the brochure. Download »
The Tolly Group evaluates
the leading NAC products
across 34 criteria points.
Download report »
Enable any means access to corporate network resources without compromising security. Download Snapshot»
Gartner 2012 NAC Magic Quadrant. Download Report»
CounterACT in Action Feature Film (<3 min) Watch Video»
Learn more about ForeScout solutions by downloading the brochure.
Download »
EMA analyst report on assuring network access control (NAC) success.
Download »
IDC analyst report on architecting a mobile security/BYOD strategy.
Download »
Accommodate personal devices on your network, without compromising security.
Employees want to use their personal mobile devices to access corporate resources. Managers want productivity gains. This consumerization of IT—also known as Bring-Your-Own-Device or BYOD—represents a daunting security challenge. How can you accommodate employee and guest requests to use their smartphones, notebooks and tablets on your network while mitigating security risks?
ForeScout helps you embrace BYOD while preserving security. ForeScout products give you real-time visibility and control over personal devices on your network. ForeScout offers a range of products that protect your network and your data, regardless of what type of device your employees are trying to use.
The Challenge
Increasingly, employees are bringing their personal devices into the office and expecting to connect them to the enterprise network and/or the Internet. In July 2011, IDC released a study indicating that 40.7% of devices used by information workers to access business applications are ones they own themselves, including laptops, smartphones, and tablets such as Apple’s iPad. That was a 10-point jump from the prior year’s study.1
Perhaps more concerning, this trend is happening faster than IT managers realize. When IDC surveyed IT managers about the number of consumer devices on their networks, they underestimated the number by 50%.
Consumer devices accessing corporate networks pose numerous security challenges. IT managers need to find a way to secure corporate data on the devices, protect the corporate network from infection by malware that may be present on the devices, and control the level of access the devices have to the corporate network.
The initial response of many IT organizations was to ban all consumer devices from their networks. But IT organizations are increasingly seeing that this is not a sustainable strategy. According to Gartner:
“Consumerization is an unstoppable trend, and most organizations need to demonstrate flexibility and allow employees to use their personal devices for work. But, they also need to establish limits and not permit every device, every operating system and every configuration. Although approaches such as server-based computing and virtualization will also be used to deal with consumerization, NAC provides the flexibility that enterprises need in a BYOD environment, while providing the controls that enable network and security managers to retain control over the network.”2
For a more extensive analysis of the risks presented by BYOD, read this whitepaper by well-known security analyst Mike Rothman and this whitepaper by the SANS Institute.
ForeScout’s Solution Set
ForeScout provides three levels of security for BYOD. Depending on your budget and your level of security requirements, you may use all three at the same time. Many of our customers find that the optimal security solution is to reserve the more expensive solution for those users with the highest need for mobile security on their devices.
The foundation of ForeScout’s mobile security solution is ForeScout CounterACT. This network-based appliance works with PCs and handheld devices. It gives you immediate, real-time visibility of every device on your network without the need for agents. No software to download, no enrollment to administer. It tells you who each user is and who owns each device. It ties into directory services and provides role-based network access control. Different users and devices get different access. The price is low, and the impact to your users is trivial because it’s transparent.
The benefit of device visibility cannot be overstated. Gartner estimates that the typical enterprise is aware of only 80% of the devices that are active on its network.2 ForeScout CounterACT shows in real-time all devices on your network, including devices that you don’t own. CounterACT categorizes devices by type—Windows, Mac, Linux, Apple iOS, Android, Blackberry, printers, etc. CounterACT also categorizes devices by ownership—corporate devices vs. personal devices. For more information on CounterACT’s visibility features, see here.
With ForeScout CounterACT, you can define and enforce different network access policies that support your mobile security strategy. For example, you might want to allow all devices that contain an MDM agent onto the production network, and send all other personal devices onto a guest network. Or, you might want to restrict personal devices with MDM agents to certain portions of your network.
If you need stronger mobile security, then we offer ForeScout CounterACT with our optional ForeScout Mobile Security Module. With this you get enhanced device security for Android and iOS devices. ForeScout Mobile Security Module gives you deep inspection of Android and iOS devices, so you can determine the security posture. Is a password configured? Is the device jailbroken? Is encyption turned on? This lets you enforce more sophisticated network access control policies than you can with just CounterACT by itself. For example, you might want to specifically block jailbroken iOS devices from your network.
In addition, ForeScout Mobile Security Module lets you manage the configuration of Apple iOS devices. The product leverages Apple’s built-in MDM API to control almost every aspect of the device, using Apple’s policy framework which is built into the iOS 4 operating system. This does not require the installation of any type of agent on the Apple device. All the visibility and control is provided natively from within the iOS operating system, using ForeScout CounterACT with ForeScout Mobile Security Module. You can directly set the password policy, remotely wipe the data, and many other functions.
In this solution tier, the impact on users remains very light, and the price is slightly higher than the first tier.
If your need for security on mobile devices is high, you will probably want to deploy a mobile device management (MDM) system. Such a system gives you extensive control over every aspect of a wide range of mobile device operating systems.
ForeScout MDM is a cloud-based MDM platform that provides end-to-end management of iOS, Android, Symbian, BlackBerry, Windows, and webOS devices. ForeScout MDM lets you manage the entire mobile device lifecycle – from enrollment to security, monitoring, application management and support.
Regardless of whether you use ForeScout MDM or another MDM system, for optimal security and operational efficiency you should tie the MDM system into ForeScout CounterACT via our optional ForeScout Mobile Integration Module. This gives you the advantage of network security PLUS unified security policy management. Rather than manage separate security policies for PCs vs. handheld devices, you can configure a single set of network access control policies in ForeScout CounterACT, and you can enforce those policies regardless of whether the user has a PC, a Mac, a smartphone or a tablet.
Note 1: http://www.cio.com.au/article/393246/idc_it_hasn_t_grasped_consumerization_trend/
Note 2: “Strategic Road Map for Network Access Control”, Gartner, 11 October 2011, Lawrence Orans and John Pescatore.
- ForeScout CounterACT limits guest access, preventing them from accessing sensitive resources
- ForeScout CounterACT ensures that guest devices meet your security policies while they are connected to your network
- ForeScout CounterACT continuously monitors guest systems to ensure that they do not attack your network.
This video demonstrates the use of ForeScout CounterACT to identify mobile handheld devices on the network and offer role-based access. Corporate devices are provided full access automatically while guests can be registered via SMS for 100% user verification.
Click image to enlarge.
Mobile DevicesForeScout CounterACT identifies handheld devices on your network – iPhone, iPad, Android, Windows Mobile, Blackberry, Nokia Symbian.
Mobile Device PropertiesForesScout mobile shows you an inventory of mobile device properties on your network.
Mobile Application InventoryForeScout Mobile provides a real-time inventory of all mobile apps on your network
Secure Document SharingCentrally manage documents, users, access controls, distribution, and policies.
MDM ActionsFrom within the ForeScout MDM management console, take actions to protect data and the device over-the-air.