NIST Drafts Mobile App Security Guidelines - InformationWeek

InformationWeek is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Government // Mobile & Wireless

NIST Drafts Mobile App Security Guidelines

National Institute for Standards and Technology issues first draft of guidelines intended to help federal agencies balance benefits and risks of third-party mobile apps.

Comment  | 
Print  | 
Newest First  |  Oldest First  |  Threaded View
User Rank: Ninja
8/30/2014 | 6:22:43 PM
Why no Guidelines for Windows or Blackberry Apps?
I was very surprised that NIST did'nt take the time and effort to also come up with Effective Guidelines List for Windows and RIM.

Sure,I am not disputing that Android and iOS are easily the dominant Mobile OSes(who control more than 70% of the smartphone market between themselves currently) but the other Two OSes are not something which can and should be neglected going ahead.

Windows in particular is finally gaining traction(especially at the Low-End) and I won't be surprised if they do go head to head with Android in the next 2 years or so.

The Lumia range is definitely turning heads currently and the HTC One Windows Phone is very catchy too.

What happens then?

Why not more coverage?

Lets also not forget the massive weakness in Smartphone Memory which was recently exploited at Defcon to show easy it is to break into Gmail App and many other such similar apps.

The Other apps hacked included H&R Block, Newegg, WebMD, Chase Bank, and Amazon.

I am hoping NIST does'nt take this issue lightly.

After all,the pace at which Android Malware is exploding(almost in tandem with increased Android Adoption) knows no bounds currently.

Alternative Mobile OSes need to see much coverage primarily because Privacy Conscious Consumers will look for them.

Even Samsung recently decided to push TIZEN in tandem with Intel .

We definitely do need more App Stores and OSes covered than just the Big Two.


User Rank: Ninja
8/30/2014 | 6:01:40 PM
Re: Mobile app security can't just be a government problem

I have a strong feeling that you are quite right and accurate here.

Most Organizations don't have the time and inclination to go through all the Apps Permissions Jargon and what not for most Employees.

They would rather just hand them the Phones and ask them to get on with the Job.

The end result can end up being very scary and disastrous for all concerned.

Sad but true.


User Rank: Ninja
8/30/2014 | 5:32:11 PM
Re: NIST Guidelines Not Very Realistic

Actually if One looks at these Guidelines(Given that they are almost exclusively aimed at Public Sector Enterprises),its a good list.

It forces not just in-house App Developers (at Public Sector Companies)but also anyone targetting Public Sector Companies to develop less Privacy Intrusive Apps if they want to gain such traction there.

I think its a really-really great list and should be enforced strongly by Individual IT Departments.


User Rank: Ninja
8/28/2014 | 5:01:16 PM
NIST Guidelines Not Very Realistic
The problem with the NIST guidelines is that every single app demands access to contacts, among other intrusive rights demanded.  Of course, the user has the option of not granting that particular privilege, in which case, the app just won't install/work correctly.  
David F. Carr
David F. Carr,
User Rank: Author
8/28/2014 | 4:32:37 PM
Mobile app security can't just be a government problem
I suspect to a large extent enterprises outside of the public sector are in no better shape for assessing the security of mobile apps.
10 Ways to Prepare Your IT Organization for the Next Crisis
Cynthia Harvey, Freelance Journalist, InformationWeek,  5/20/2020
IT Spending Forecast: Unfortunately, It's Going to Hurt
Jessica Davis, Senior Editor, Enterprise Apps,  5/15/2020
Helping Developers and Enterprises Answer the Skills Dilemma
Joao-Pierre S. Ruth, Senior Writer,  5/19/2020
White Papers
Register for InformationWeek Newsletters
Current Issue
Key to Cloud Success: The Right Management
This IT Trend highlights some of the steps IT teams can take to keep their cloud environments running in a safe, efficient manner.
Flash Poll