How Colligo Helped Novartis Trust iPads On SharePoint - InformationWeek

InformationWeek is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

IoT
IoT
Mobile
News
5/29/2012
05:54 PM
Connect Directly
LinkedIn
Twitter
RSS
E-Mail
50%
50%

How Colligo Helped Novartis Trust iPads On SharePoint

Penetration testing found only Colligo met Novartis' rigorous criteria for allowing iPads to access sensitive corporate data on SharePoint.

 7 Examples: Put Gamification To Work
7 Examples: Put Gamification To Work
(click image for larger view and for slideshow)
When Colligo Networks asked Markus Bosch to test its iPad app for secure access to SharePoint, it couldn't have picked a better time.

Bosch is a solution architect at Novartis International, responsible for meeting the collaboration needs of the drug maker's headquarters staff. Colligo Networks makes several SharePoint-centric products for file management and synchronization. Novartis was already using the Colligo Contributor Add-in for Outlook to make it easy to upload and download files through the SharePoint interface and share content through the portal, rather than as email attachments. When he "stumbled over Colligo again" at a SharePoint conference last year, Bosch had just received a request from Novartis' investor relations department for iPad access to documents stored in SharePoint.

While he understood the investor relations team's desire to do more with their iPads, Bosch was also cautious because of the sensitivity of the information they worked with. "We could lose a lot of money if the wrong information is disclosed," he said in an interview.

[ Is it all about Apple? Read BYOD Policy Or Buy Everyone An iPhone. ]

Colligo tested its Colligo Briefcase iPad app against Novartis' requirements, and in the end Bosch was convinced. He had an Ernst & Young consultant run a series of penetration tests on Colligo Briefcase and other file management apps he was considering, including GoodReader, SharePlus, and Aircreek's Filamente. The testing looked both at the apps in normal use and their vulnerability to "jailbreaking" techniques, where an attacker might subvert the iPad's normal hardware and software security.

With the other tested apps, authentication methods could be bypassed and jailbreaking would allow someone to read content directly from the iPad's memory, Bosch said. "But with Colligo Briefcase, he didn't get anywhere." Because the application provides its own encryption, documents in memory were unreadable, even on a jailbroken device.

"When we started looking at the iPad, we realized there were a lot of issues that needed to be resolved to make it a secure environment to put corporate data," Colligo CEO Barry Jinks said. Jailbreaking was one of the items on that list, along with addressing scenarios where an iPad is lost or stolen, or when an employee leaves the company with corporate data stored on his personal device.

Mobile device management software exists to address these issues across a variety of devices, but applications for managing business data must address them, too, Jinks said. These products typically promise the ability to initiate a "remote wipe" that will clean the device of corporate data, but, according to Jinks, "some apps leave remnants of themselves on the device when it's wiped, and there are a lot of apps you can buy in the app store that can't easily be remotely wiped."

Many apps, emphasizing convenience for the user, will also prepopulate the user name and often the password for access to network systems, "which is not very secure if the device gets stolen," Jinks said. "They depend on the keycode locking of the device. We believe there needs to be app-by-app keycode locking."

Bosch said his selection of Colligo Briefcase only applies to the holding company that oversees the firm's international operations and, so far, has only 22 users in investor relations. However, there are another 18,000 iPads in use across the company, he said, so Colligo could have a broader opportunity if other divisions follow its lead.

Follow David F. Carr on Twitter @davidfcarr. The BrainYard is @thebyard and facebook.com/thebyard

The Enterprise 2.0 Conference brings together industry thought leaders to explore the latest innovations in enterprise social software, analytics, and big data tools and technologies. Learn how your business can harness these tools to improve internal business processes and create operational efficiencies. It happens in Boston, June 18-21. Register today!

We welcome your comments on this topic on our social media channels, or [contact us directly] with questions about the site.
Comment  | 
Print  | 
More Insights
News
Think Like a Chief Innovation Officer and Get Work Done
Joao-Pierre S. Ruth, Senior Writer,  10/13/2020
Slideshows
10 Trends Accelerating Edge Computing
Cynthia Harvey, Freelance Journalist, InformationWeek,  10/8/2020
News
Northwestern Mutual CIO: Riding Out the Pandemic
Jessica Davis, Senior Editor, Enterprise Apps,  10/7/2020
White Papers
Register for InformationWeek Newsletters
2020 State of DevOps Report
2020 State of DevOps Report
Download this report today to learn more about the key tools and technologies being utilized, and how organizations deal with the cultural and process changes that DevOps brings. The report also examines the barriers organizations face, as well as the rewards from DevOps including faster application delivery, higher quality products, and quicker recovery from errors in production.
Video
Current Issue
[Special Report] Edge Computing: An IT Platform for the New Enterprise
Edge computing is poised to make a major splash within the next generation of corporate IT architectures. Here's what you need to know!
Slideshows
Flash Poll