Take Action to Avoid Mobile Device Geolocation Risk - Slide 6

Email     |     Share  
1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13
Next What Can the Enterprise Do?-6 Next

What Can the Enterprise Do?

Take into account the applicable legislation and regulations on privacy around the world, which differ by country.

Twenty-eight percent of U.S. adults use location-based applications such as Facebook, Groupon and Google Maps on their mobile devices, and that number is expected to grow significantly. But a new ISACA white paper cautions that regulating the use of geolocation data is still in its infancy, so individuals must be aware of the information they are sharing and enterprises must act now to protect themselves and the information they provide, collect and use.

Geolocation uses data acquired from a computer or mobile device to identify a physical location. Applications using this technology offer consumers greater convenience, discounted prices and easy information sharing, and enable enterprises to deliver more personalized customer service and offers. But as geolocation services become more common, the need for data management and enterprise controls increases significantly.

As ISACA’s new white paper, “Geolocation: Risk, Issues and Strategies,” points out, malicious use of geolocation data can put both an individual and an enterprise at risk. When a person’s personal information, such as gender, race, occupation and financial history, is combined with information from a GPS and geolocation tags, the data can be used by criminals to identify an individual’s present or future location. This raises the potential of threats ranging from burglary and theft to stalking and kidnapping.

“As the number of geolocation users grows and the proliferation of mobile devices continues, the prospect of individual or enterprise information becoming available to hackers or other unauthorized users is a significant concern,” said Marios Damianides, CISM, CISA, CA, CPA, past international president of ISACA and partner, Advisory Services, at Ernst & Young. “We need policies that will establish ‘privacy by design’ to instill trust across the enterprise and guard against malicious use of location information.”

Regulators are aware of such concerns and are moving to enact rules regarding how companies can use geolocation data. Current U.S. legislation proposed by Sens. Al Franken (D-Minn) and Richard Blumenthal (D-CT) would restrict whether companies can store individual location data obtained from mobile devices, and a proposed amendment to the Children’s Online Privacy Protection Act (COPPA) from the U.S. Federal Trade Commission addresses the collection of geolocation data from children under age 13.

Collecting and using geolocation data pose risk to the enterprise, including:

  • Privacy:  Geo-tagging is implemented by users, but there may be multiple entities that have access to the data, including the service provider and wireless access points/developers. Users can’t always identify (or aren’t always aware of) the source or owner of their location data.
  • Enterprise reputation: When breaches occur or policies have not been communicated clearly to customers, organizations risk negative perceptions of their brand.
  • Compromise of sensitive information: The physical location of an enterprise and its remote facilities/equipment can be identified, increasing potential for loss of sensitive information through a variety of attacks. 

“We live in a mobile world and geolocation is here to stay. It brings obvious benefits both to individuals and enterprises, but if not managed properly the associated risk will be substantial,” said Ramsés Gallego, member of ISACA’s Guidance and Practices Committee and security strategist and evangelist at Quest Software.  “It directly impacts individuals’ and enterprises’ privacy and confidentiality, and the consequences of poor governance over geolocation can be disastrous.”

More Slideshows:


Ten Early Warning Signs of Fraud in OrganizationsWarning signs of fraud and actions that can be taken to counter the risks.

The Top 10 Strategic Technologies for 2012 Use this list in your strategic planning for 2012.

The 10 Things Every Business Should Know About B2B E-commerceTips to consider before adopting a B2B e-commerce platform.

 

Related Topics : Unisys, Stimulus Package, Security Breaches, Symantec, Electronic Surveillance

 
More Slideshows

Privacy rollback Security Pros Give Their Opinions on ISP Data Privacy Rollback

IT staff, organization leaders, and the average citizen have all expressed levels of concern over the FCC about-face in regard to ISP privacy. Here’s what the security experts say. ...  More >>

IT security skills 7 Top Skills for Security Pros

Executives at several top tech firms outline the skills they need now and in the near future, including IaaS and IoT security expertise. Other skills listed may surprise you. ...  More >>

IT security careers The Most In-Demand Security Jobs and How to Get Them

Security professionals are in demand right now, and entry-level security jobs generally fall into either an engineer or analyst role. Find out more about required skills and career paths. ...  More >>

Subscribe to our Newsletters

Sign up now and get the best business technology insights direct to your inbox.