Filter by Category

Upcoming FISMA Update to Protect Mobile Data

FISMA to improve mobile security

Mobile security has been a frequent topic of discussion in recent months. For those in the public sector, a lack of compliance requirements for mobile devices has sparked several concerns. Is it safe to connect to the cloud with a device that isn’t protected? How many cell phones and tablets are at risk of being compromised by everyday use, like connecting to a vulnerable wireless hotspot or downloading a seemingly harmless application?

FISMA, the Federal Information Security Management Act, requires government agencies to create, document, and implement a plan that ensures the security of their network and information systems. This covers devices like workstations, laptops, and desktops, but it sadly lacks mobile guidelines.

Thankfully, this oversight may soon change. The Department of Homeland Security (DHS) has turned their focus to mobile security, with plans to implement new research programs and update FISMA with new mobile requirements for government workers. In April 2017, they published a Study on Mobile Device Security with consultation from the National Institute of Standards and Technology (NIST). Their top consideration moving forward? Enhance FISMA metrics to focus on mobile device security.

A mobile addition to FISMA compliance couldn’t be more timely. According to this article, “67% of companies included in a recent Ponemon Institute survey have experienced a breach from an employee’s mobile device.” Other shocking statistics, like the hefty, $10,000 pricetag that comes with investigating and repairing just one infected device, capitalize on the very real need for mobile security.

Furthermore, attacks on mobile applications and mobile data, especially those belonging to federal employees, are on the rise. The Business of Federal Technology states in an article on prioritizing mobile security: “Because of the combination of features only available on mobile—connected via Wi-Fi or cell networks with voice, camera, email, location, passwords, contact lists and more—these devices have become an attractive target for cybercriminals and nation-states looking to spy on government agencies, infrastructure providers and others.”

There are steps organizations can take now to prioritize the security of their employees’ mobile devices. Some of these include mandatory use of multi-factor authentication, only allowing use of work-provided devices during normal business hours, limiting what each device can access and download, and requiring frequent OS updates. We also suggest reviewing your current cybersecurity policies in anticipation for FISMA’s mobile security update.

As of the publication of this post, FISMA may roll out requirements for mobile security in 2018.

Latest Posts


Which is Better? - AS2 vs. AS4

August 16, 2019

AS2 vs. AS4 AS2 and AS4 are both popular file transfer protocols that allow businesses to exchange data securely with their business partners. However, what is the difference between them, and…


Why You Should Migrate from Your Current MFT Software

August 12, 2019

Is Your MFT Solution Keeping Up with Your File Transfer Requirements? With the increasing responsibilities IT professionals must juggle, including managing a myriad of daily tasks, addressing…


GDPR: Understanding the 8 Rights of Data Subjects

August 5, 2019

Find out what these new rights mean for your organization and how you can prepare. GDPR…


Think Your Customer Data was Exposed? Follow These Steps

July 31, 2019

When a prospect or customer shares personal data with a business, they expect their information will be stored securely, kept safe from vulnerabilities, and used only for the purposes with which it…


Is FTP Dead?

July 29, 2019

Is FTP still a viable option for sending file transfers? While organizations across all industries have started shifting to secure FTP protocols like SFTP and FTPS, a surprising number of businesses…