[unisog] Blackberry timeout - summary

Melissa Muth muthm at isc.upenn.edu
Thu Jun 5 20:48:19 GMT 2008


On 6/5/08 3:22 PM, "Andrew Bell" <andrewbell at trentu.ca> wrote:

> As promises, a summary of off-list responses:
>
> Only one respondent has a specific policy in place, and they use a
> timeout value of one hour.  Their policy applies to all managed
> handhelds, regardless of whether they contain "sensitive" data

Here's the link to that policy:
http://www.net.isc.upenn.edu/policy/approved/20080407-serverpda.html

> My position on sensitive data is that the end
> user does not control what gets emailed to them, therefore all devices
> are assumed to contain data which must be protected.

Indeed, this is part of the reason we didn't limit the covered devices.

Melissa Muth
Sr. Information Security Analyst
Information Systems & Computing
University of Pennsylvania
muthm at isc.upenn.edu   215-573-6798

>
> Thank you all for your input.
>
> Andrew Bell
> Manager, Digital Service Delivery & Administration
> Trent University
> Peterborough, Ontario
>
> _______________________________________________
> unisog mailing list
> unisog at lists.dshield.org
> https://lists.sans.org/mailman/listinfo/unisog




More information about the unisog mailing list