2016 NLC-RISC Trustees Conference...1 2016 NLC-RISC Trustees Conference Issues and Consideraons in...

33
1 2016 NLC-RISC Trustees Conference Issues and Considera:ons in BYOD (Bring Your Own Device) Employees are increasingly bringing their own personal electronic devices, including mobile phones and tablets, into the workplace. Some employers believe that BYOD saves money, and many employees prefer to use just one set of devices. It seems like a win-win, but there are real security and data breach hazards associated with permiEng employee-owned and -maintained technology in the workplace, especially if the employer does not adopt and follow a thorough BYOD policy. In the 21 st century workplace, many organizaGons allow employees to access corporate data from outside of the workplace. Email access is most common, but oHen staff are also accessing applicaGons in the “cloud” or storing sensiGve informaGon on removable media (usb drives, cd/dvds, etc). Pools are affected if they permit BYOD in their own workforce or cover members for data breach. Ryan Draughn, CIO/Business Director, NC League of Municipali=es Friday, May 6th 10:45am – 12:00 pm

Transcript of 2016 NLC-RISC Trustees Conference...1 2016 NLC-RISC Trustees Conference Issues and Consideraons in...

Page 1: 2016 NLC-RISC Trustees Conference...1 2016 NLC-RISC Trustees Conference Issues and Consideraons in BYOD (Bring Your Own Device) Employees are increasingly bringing their own personal

1

2016NLC-RISCTrusteesConferenceIssuesandConsidera:onsinBYOD(BringYourOwnDevice)Employeesareincreasinglybringingtheirownpersonalelectronicdevices,includingmobilephonesandtablets,intotheworkplace.SomeemployersbelievethatBYODsavesmoney,andmanyemployeesprefertousejustonesetofdevices.Itseemslikeawin-win,buttherearerealsecurityanddatabreachhazardsassociatedwithpermiEngemployee-ownedand-maintainedtechnologyintheworkplace,especiallyiftheemployerdoesnotadoptandfollowathoroughBYODpolicy.Inthe21stcenturyworkplace,manyorganizaGonsallowemployeestoaccesscorporatedatafromoutsideoftheworkplace.Emailaccessismostcommon,butoHenstaffarealsoaccessingapplicaGonsinthe“cloud”orstoringsensiGveinformaGononremovablemedia(usbdrives,cd/dvd’s,etc).PoolsareaffectediftheypermitBYODintheirownworkforceorcovermembersfordatabreach.RyanDraughn,CIO/BusinessDirector,NCLeagueofMunicipali=esFriday,May6th10:45am–12:00pm

Page 2: 2016 NLC-RISC Trustees Conference...1 2016 NLC-RISC Trustees Conference Issues and Consideraons in BYOD (Bring Your Own Device) Employees are increasingly bringing their own personal

2

EmployeeswhobringtheirowncompuGngdevices–suchassmartphones,laptops,andtablets-totheworkplaceforuseandconnecGvityonthecorporatenetwork.

BYOD–Whatisit?

BYOD=BringYourOwnDevice

Page 3: 2016 NLC-RISC Trustees Conference...1 2016 NLC-RISC Trustees Conference Issues and Consideraons in BYOD (Bring Your Own Device) Employees are increasingly bringing their own personal

3

1956:Firstharddriveforsaleholds5MBofdataatacostof$50,000.2016:SanDiskCruzersells64GB(64,000MB)USBdrivefor$15.

HistoryFunFact

WhowasmanufacturerofthatfirstHardDrive?

Page 4: 2016 NLC-RISC Trustees Conference...1 2016 NLC-RISC Trustees Conference Issues and Consideraons in BYOD (Bring Your Own Device) Employees are increasingly bringing their own personal

The“BYOD”Hype

Mobility BestBuyEffect

EaseofUse GeneraGonal

©UNCSchoolofGovernment-EvaluaGngBYOD

Page 5: 2016 NLC-RISC Trustees Conference...1 2016 NLC-RISC Trustees Conference Issues and Consideraons in BYOD (Bring Your Own Device) Employees are increasingly bringing their own personal

5

GoodReasonsforEmbracing

•  StaffcancarryaSingleDevice•  StaffcanusethedeviceofTHEIRchoice

•  TendtobemoreproducGve/complainless.•  Theytendtobecerprotectthedevice.

•  ChooseprotecGvecasesandscreencovers.•  Chooseowninsurance/protecGonplans.

•  Freedomtodeploypersonalappsanduseforleisureaswellasbusiness.•  NavigaGonalapps,Bookreaders,PDFtools.•  Music/Entertainmentapps.•  FreeandNon-freeapps.

Page 6: 2016 NLC-RISC Trustees Conference...1 2016 NLC-RISC Trustees Conference Issues and Consideraons in BYOD (Bring Your Own Device) Employees are increasingly bringing their own personal

6

MoreReasonsforEmbracing

•  It’stheirs,evenaHertheyleaveemployment.

•  Upgradecyclemorefrequent,InsteadoforganizaGonalrefreshofdevices(oHen3-4years),employeescanrefreshsooner.

•  Mayhelpeaseemploymentequityissues.•  GeneraGonalAppeal(notjusttalkingMillennials).

•  Fitslifestyleofworkingwhenconvenient.

Page 7: 2016 NLC-RISC Trustees Conference...1 2016 NLC-RISC Trustees Conference Issues and Consideraons in BYOD (Bring Your Own Device) Employees are increasingly bringing their own personal

7

GoodReasonsforNOTEmbracing

•  Security–ORLACKTHEREOF!•  Howdoyouenforcetheneededpolicies.•  TheH/Loss–Itwillhappen.

•  LackofcompleteorganizaGoncontrolofdevice.•  Youmaybeabletoapplygeneralizedpolicies,butfull

controlwithoutownershipmaybehardtoachieve.•  SecurityTools–Andissuesdeploying/enforcing.

•  WorkplaceRulesmaychange•  WhataretheyusingitforduringthemeeGng?•  Blurringoflinesofpersonaluse/businessuse.•  Humansmakemistakes;howwilltheorganizaGon

addressthis?(Ex.answeringthephoneinappropriately)

Page 8: 2016 NLC-RISC Trustees Conference...1 2016 NLC-RISC Trustees Conference Issues and Consideraons in BYOD (Bring Your Own Device) Employees are increasingly bringing their own personal

8

MoreReasonsforNOTEmbracing

•  LaborLaws:Cannon-exemptstaffuse?•  PrivacyConcerns•  It’stheirdevice,areyoureadyhowtheymayuseit?

•  Areyouopentopolicingtheirbehavior?•  Scopecouldgowild(laptops,tablets,smartphones,watches,usbdrives,bookreaders,digitalcameras,GoPros,wifi’s/mifi’s,etc.

Page 9: 2016 NLC-RISC Trustees Conference...1 2016 NLC-RISC Trustees Conference Issues and Consideraons in BYOD (Bring Your Own Device) Employees are increasingly bringing their own personal

9

BYODConsideraGons

Page 10: 2016 NLC-RISC Trustees Conference...1 2016 NLC-RISC Trustees Conference Issues and Consideraons in BYOD (Bring Your Own Device) Employees are increasingly bringing their own personal

Thingsarechangingaroundus

•  “Consumer”orpersonalsoHwaremakingitswayintobusiness(Skype,Dropbox,iCloud,etc.)

•  CloudstorageandSoHwareasaService(SaaS)becomingmorecommonplace.

Page 11: 2016 NLC-RISC Trustees Conference...1 2016 NLC-RISC Trustees Conference Issues and Consideraons in BYOD (Bring Your Own Device) Employees are increasingly bringing their own personal

11

CanyourITDepartmentHandleit?

Structural Human Resource

Culture Political©UNCSchoolofGovernment-EvaluaGngBYOD

Page 12: 2016 NLC-RISC Trustees Conference...1 2016 NLC-RISC Trustees Conference Issues and Consideraons in BYOD (Bring Your Own Device) Employees are increasingly bringing their own personal

Structural

•  ITassumesanewrole.•  TradiGonalbreakfixisnowreplacedwithbecomingatrustedbusinessadvisor.

•  Userempowermentversuscommandandcontrol.

Page 13: 2016 NLC-RISC Trustees Conference...1 2016 NLC-RISC Trustees Conference Issues and Consideraons in BYOD (Bring Your Own Device) Employees are increasingly bringing their own personal

HumanResource•  Righttypeofskillsetswithinthedepartment.

•  Atechnologistversustechnician.–  Findingtherightbalanceiscrucial.

•  SoHskills/CommunicaGonsskillsareamust.

Page 14: 2016 NLC-RISC Trustees Conference...1 2016 NLC-RISC Trustees Conference Issues and Consideraons in BYOD (Bring Your Own Device) Employees are increasingly bringing their own personal

Cultural/Symbolic•  ITasabusinesspartner– Notacostcenter

•  Employeeempowerment•  WetradiGonallymanagedthenetwork– WhatdoweulGmatelyneedtocareabout

Page 15: 2016 NLC-RISC Trustees Conference...1 2016 NLC-RISC Trustees Conference Issues and Consideraons in BYOD (Bring Your Own Device) Employees are increasingly bringing their own personal

PoliGcal

•  ThishastheabilitytochangethePercepGonofIT.

•  InnovaGvevs.ReacGonary.•  Embracingchange.

Page 16: 2016 NLC-RISC Trustees Conference...1 2016 NLC-RISC Trustees Conference Issues and Consideraons in BYOD (Bring Your Own Device) Employees are increasingly bringing their own personal

16

Believeitornot,TechnologyChanges

Howsoonbeforewedon’tevenhave“PERSONAL”devices?

Page 17: 2016 NLC-RISC Trustees Conference...1 2016 NLC-RISC Trustees Conference Issues and Consideraons in BYOD (Bring Your Own Device) Employees are increasingly bringing their own personal

17

Page 18: 2016 NLC-RISC Trustees Conference...1 2016 NLC-RISC Trustees Conference Issues and Consideraons in BYOD (Bring Your Own Device) Employees are increasingly bringing their own personal

18

It’stheENVIRONMENT,NottheDevice•  In10years,wemaynotbecarryingaroundbricksorthinslatesaroundinourpockets.•  Accessingyour“PROFILE”orEnvironmentonshareddevices.•  Datainthecloud(BusinessandPersonal).•  SaaS(SoHwareasaService)isalreadycommonplace.•  BusinessEnvironmentvsPersonalEnvironment

Page 19: 2016 NLC-RISC Trustees Conference...1 2016 NLC-RISC Trustees Conference Issues and Consideraons in BYOD (Bring Your Own Device) Employees are increasingly bringing their own personal

19

Thetelevisiontook13yearstoreachamarketaudienceof50million.

TheiPodtook3yearstoreachamarketaudienceof50million

HistoryFunFact#2

WhoismanufactureroftheiPOD?

Page 20: 2016 NLC-RISC Trustees Conference...1 2016 NLC-RISC Trustees Conference Issues and Consideraons in BYOD (Bring Your Own Device) Employees are increasingly bringing their own personal

20

InteresGngStaGsGcs

Page 21: 2016 NLC-RISC Trustees Conference...1 2016 NLC-RISC Trustees Conference Issues and Consideraons in BYOD (Bring Your Own Device) Employees are increasingly bringing their own personal

21

Page 22: 2016 NLC-RISC Trustees Conference...1 2016 NLC-RISC Trustees Conference Issues and Consideraons in BYOD (Bring Your Own Device) Employees are increasingly bringing their own personal

22

Gartnerpredictsby2017,50%ofemployerswillrequireemployeestosupplytheirowndeviceforwork

purposes.

(source:“BringYourOwnDevice:TheFactsandtheFuture”Gartner2013).

Page 23: 2016 NLC-RISC Trustees Conference...1 2016 NLC-RISC Trustees Conference Issues and Consideraons in BYOD (Bring Your Own Device) Employees are increasingly bringing their own personal

23

•  ProducGvity,flexibilityandremoteworkinghaveemergedasthetopthreedriversofBYOD.

hcp://www.macquarietelecom.com/resources/blog/25/06/2015/byod-top-6-trends/

REFINEMENTOFBENEFITS

Page 24: 2016 NLC-RISC Trustees Conference...1 2016 NLC-RISC Trustees Conference Issues and Consideraons in BYOD (Bring Your Own Device) Employees are increasingly bringing their own personal

24

•  Employeesarefedupwithappsthatchainthemtothedesktop.

•  Instead,theywanttousetheirshinynewiPadsandAndroidtabletsthattheyunwrappedovertheholidaysforwork.

•  SaaSenablingthistohappen.

hcp://www.macquarietelecom.com/resources/blog/25/06/2015/byod-top-6-trends/

ENDOFLEGACYAPPLICATIONS

Page 25: 2016 NLC-RISC Trustees Conference...1 2016 NLC-RISC Trustees Conference Issues and Consideraons in BYOD (Bring Your Own Device) Employees are increasingly bringing their own personal

25hcps://www.sungardps.com/state-mobility-government/

BYODinthePublicSector

Increasingly,governmentworkersare:•  UsingtabletstoconductbuildinginspecGons•  IssueparkingGcketsandcollectfeesfromresidents.•  TherelatedBYOD(BringYourOwnDevice)movementhasusheredinaneweraof

“govies”whocanrespondtotheirconsGtuentsinreal-Gme.TheirresponsecapacityisnolongerGedtoaspecificdeskinagovernmentoffice–inquiriesmaybeansweredfromanylocaGonandincreasinglymaycomeduringeveninghoursorweekends.

•  LookoutInc.surveyedfederalagenciesandfoundthat50%ofgovernmentworkersnowusetheirpersonaldeviceforworkemailand49%usethosedevicestodownloadworkrelateddocuments.

Page 26: 2016 NLC-RISC Trustees Conference...1 2016 NLC-RISC Trustees Conference Issues and Consideraons in BYOD (Bring Your Own Device) Employees are increasingly bringing their own personal

26

BYOD:ImpacttoPoolsPosi=vePossibili=es:•  CompeGGveAdvantages

•  Morepersonalizedandindividualservice•  Increasedcustomerservice•  Flexibilityinworkhourspossibly•  Increasedemployeemorale

Nega=vePossibili=es:•  Hardertomanage•  Employmentliabilityclaimsfrommembers•  CyberRisk/DataBreachnoGficaGonriskincreases

hcp://www.propelics.com/how-mobile-impacts-the-insurance-industry-in-2016/hcp://www.propertycasualty360.com/2014/04/02/managing-risk-for-bring-your-own-device-companies)

Page 27: 2016 NLC-RISC Trustees Conference...1 2016 NLC-RISC Trustees Conference Issues and Consideraons in BYOD (Bring Your Own Device) Employees are increasingly bringing their own personal

27

BYODProgramGoals

•  IncreaseemployeeproducGvitythroughmobility•  DriveemployeesaGsfacGonandretenGon•  DrivecompeGGvedifferenGaGon•  ReducesecuritythreatsbyinsGtuGngformalpolicyandprocedures

•  ReducedevicemanagementandprocurementGmeandcost•  ReduceGmeandcostsassociatedwithsupportcalls•  Simplifyemployeeandcontractoronboarding

Page 28: 2016 NLC-RISC Trustees Conference...1 2016 NLC-RISC Trustees Conference Issues and Consideraons in BYOD (Bring Your Own Device) Employees are increasingly bringing their own personal

28

ToolstoManageBYOD

•  MobileDeviceManagement•  Airwatch,Maas360,MicrosoHMDM,etc.

•  BestPracGces–Forcescreenlockpasswords,biometrics,agentsoHware

•  SpecialtyVendorSoluGons–SpecificApplicaGonAccessTools.

•  WirelessAccess&Governance•  Trainingforusers

Page 29: 2016 NLC-RISC Trustees Conference...1 2016 NLC-RISC Trustees Conference Issues and Consideraons in BYOD (Bring Your Own Device) Employees are increasingly bringing their own personal

29

BYODSecurityConcerns

•  DATABREACHES–DoyouknowyourresponsibiliGes?•  YouareLEGALLYresponsibleforprotecGngprivatedataforyourorganizaGon.•  MostallstatelawsrequirenoGficaGonlecerstobesenttociGzensifabreach

occurs.•  LegalFees•  NoGficaGonCosts•  ForensicdataCosts•  DamagetoreputaGon

Page 30: 2016 NLC-RISC Trustees Conference...1 2016 NLC-RISC Trustees Conference Issues and Consideraons in BYOD (Bring Your Own Device) Employees are increasingly bringing their own personal

30

BYODSamplePolicyHighlights•  PrimarygoalistheprotecttheintegrityofconfidenGalmemberandbusinessdatathatresidesinyourcompanyinfrastructure.

•  StresstheimportanceofdataprivacyandemployeeresponsibiliGes.

•  ListWHOitcovers.(FTEs,PTEs,temps,interns,boardmembers,etc.)

•  StatethatNONsancGoneduse(illegalacGvity,etc.)strictlyprohibited.•  Likelycoveredinyourpersonnelpolicyorshouldbe.

•  Whereappropriate,i.e.securedandprivatedataareas,willrequiremulG-factorauthenGcaGon.(HIPAA/PCI/PII)

Page 31: 2016 NLC-RISC Trustees Conference...1 2016 NLC-RISC Trustees Conference Issues and Consideraons in BYOD (Bring Your Own Device) Employees are increasingly bringing their own personal

31

BYODSamplePolicyHighlights–Cont.•  ListoutspecificrequirementsforyourorganizaGon.•  MustUseSTRONGpassword(somemgttoolscanenforcethis)

•  MustreporttoIT/HRifdeviceisstolenorlostimmediately.AndinformthatITandOrganizaGonhasrighttorefuseconnecGonsand/orwipethedeviceifnecessary.

•  BespecificaboutwhatIT’sroleisinsupporGngpersonaldevices.•  Supportofphysicaldevice?•  AssistancewithsynchronizaGons?

•  MAKEEMPLOYEESSIGNTHEPOLICY!

Page 32: 2016 NLC-RISC Trustees Conference...1 2016 NLC-RISC Trustees Conference Issues and Consideraons in BYOD (Bring Your Own Device) Employees are increasingly bringing their own personal

32

WhatistheonlystateinAmericathatcanbespelledbytypingononlyonerowofatradiGonalEnglishQWERTYkeyboard?

HistoryFunFact#3

ALASKA

Page 33: 2016 NLC-RISC Trustees Conference...1 2016 NLC-RISC Trustees Conference Issues and Consideraons in BYOD (Bring Your Own Device) Employees are increasingly bringing their own personal

QuesGonsandDiscussion