01.11.2012 Views

iOS Hardening Configuration Guide - DSD

iOS Hardening Configuration Guide - DSD

iOS Hardening Configuration Guide - DSD

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Conteent<br />

Filterinng<br />

Access to intranet sites, and some s mail, contact or calendaring<br />

c data can bbe<br />

achieved d via<br />

reversee<br />

proxies annd<br />

content fi ilters. Theree<br />

are multip ple solutions s in this spaace<br />

such as IIS<br />

from Miicrosoft,<br />

Moobile<br />

Access s Server froom<br />

Apple, and<br />

a wide variety v of othher<br />

solution ns (e.g.<br />

from Cisco<br />

or F5 nnetworks<br />

).<br />

Filteringg<br />

Exchangee<br />

Active Syn nc data prodducts<br />

such as JanusGA ATE Mobilee<br />

(http://wwww.janus.nnet.au/janus<br />

sGATE/Mobbile)<br />

can be e used to en nsure email sent to Exc change<br />

ActiveSSync<br />

devices<br />

has appro opriate privaacy<br />

marking gs for the classificationn<br />

the device e is<br />

approveed<br />

to by an agency. Th his approach<br />

can allow w for an asym mmetric straategy<br />

– mobile<br />

devicess<br />

only receivve<br />

email content<br />

at a cclassification<br />

n appropriat te to the deevice,<br />

as we ell as<br />

have poolicy<br />

and coontrols<br />

appli ied to the email<br />

conten nt.<br />

In this sscenario,<br />

the<br />

agency’s Wide Area Network (W WAN) secur rity domain is NOT exte ended<br />

out to thhe<br />

mobile ddevice,<br />

and there is no need to low wer the classification<br />

off<br />

the agency<br />

WAN.<br />

Such soolutions<br />

cann<br />

be used to o redact speecific<br />

content<br />

patterns from emailss<br />

sent via EAS, E<br />

e.g. to sscrub<br />

creditt<br />

card numb bers from alll<br />

emails syn nced to mob bile devicess.<br />

This class s of<br />

tools caan<br />

also facilitate<br />

correc ct protectivee<br />

marking of f email com ming from moobile<br />

device es<br />

without direct on-device<br />

suppo ort for Austrralian<br />

Gove ernment marking<br />

standdards.<br />

For further<br />

f<br />

informaation<br />

see thee<br />

ISM sectio on on Conteent<br />

Filtering g.<br />

Examplee<br />

of Mail Ap pp interfacee<br />

when Jan nusGATE Mobile M bloccks<br />

email<br />

20 | Defence S ignals<br />

Directo<br />

rate

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!