<Insert Picture Here>
Oracle Mobile Security Management
Angelo Maria Bosis
Technology Sales Consulting Director
Safe Harbor Statement
The following is intended to outline our general product direction. It is intended for information purposes only, and may not be incorporated into any contract. It is not a commitment to deliver any material, code, or
functionality, and should not be relied upon in making purchasing decisions. The development, release, and timing of any features or
functionality described for Oracle’s products remains at the sole discretion of Oracle.
Agenda
Changing Mobile Security Requirements
Oracle Mobile Security Vision
Identity Management and Mobile Security
Mobile Security Solution Overview
85% of organizations allow employees to bring their own devices
to work.
- IDG Research Services
More than 50% of organizations rely on their users to protect
personally owned devices.
- SANS Institute Research Survey
Over 70% of mobile professionals will conduct their work
on personal smart devices by 2018.
- Forrester
90% of CIO expect to deploy more than
25 mobile apps in 2014.
Forbes: Mobile Business Statistics For 2012
Organizations
Struggle to
Secure Mobile
BYOD
(
COPE
) is the Norm and Security Measures are Inadequate
Changing Mobile Requirements
•
Mobile is a new threat vector
•
BYOD poses security risks
•
IT wants security while employees want
user-experience
•
Consumerization of IT is pushing the limits of
enterprise productivity
•
Infrastructure siloes are increasing IT complexity
Agenda
Changing Mobile Security Requirements
Oracle Mobile Security Vision
Identity Management and Mobile Security
Mobile Security Solution Overview
Oracle Mobile Solution
CRM
MOBILE APPS MOBILE PLATFORM MOBILE SECURITY
ERP
Oracle Mobile Security
• Mobile Security Suite that can extend the Oracle IDM platform
• Separate personal and corporate apps and
data
• Application centric solution – avoid device
lockdown
• Extend Identity Management platform to
manage the lifecycle of applications and containers
• Extend Access Management platform to
mobile devices and applications
• Oracle/ADF Mobile Apps secure-by-default by consuming these security services
Oracle’s Mobile Security Plan
Extending IDM services
• Common users, roles, policies, access request, cert etc.
• SSO and authorization for native and browser apps
• Risk/policy based step up and strong authentication
Oracle’s Mobile Security Plan
Secure Container for App Security and Control
• Separate, protect and wipe corporate applications and data
• Strict policies to restrict users from viewing/moving data out of container
• Consistent support across multiple mobile platforms
Oracle’s Mobile Security Plan
Secure Access, Device and App Management
•
Secure communication with enterprise application servers•
No VPN and no CPU and network overhead (like IPSEC)•
Support for 3rd party and socialidentities
•
Provide context-driven, risk-aware access to enterprise apps•
Enterprise app store/catalog•
Device enrollment and provisioning•
Prevent rogue apps, access to internal network only for white-listed appsOracle’s Mobile Security Plan
• App Containerization adds security layer for bespoke and COTs apps after development
• Decouple security deployment & app development
• Injection-based approach. No SDK.
• SSO, secure access and DLP enforcement
Agenda
Changing Mobile Security Requirements
Oracle Mobile Security Vision
Identity Management and Mobile Security
Mobile Security Solution Overview
The Extended Enterprise
A Platform for Enterprise, Cloud & Mobile
One Identity Platform
Open, Integrated, Best of Breed
DIRECTORY SERVICES IDENTITY GOVERNANCE ACCESS MANAGEMENT To Handle 100s of Millions of Users Supporting Mobile, Social and Cloud
Agenda
Changing Mobile Security Requirements
Oracle Mobile Security Vision
Identity Management and Mobile Security
Mobile Security Solution Overview
Oracle Identity Management
Extending the Platform with a Discreet Mobile Security Solution
Identity Governance
Access Request Approval Workflows Automated Provisioning HR Reconciliation
Access Certification and SOD Role Lifecycle Management Privileged Account Management
User Management & Self Service Entitlement Catalogue/App Store
Access Management
Web Single Sign-on Federation
Social Identity Access Externalized Authorizations SOA and API Security Integrated ESSO Token Services
Mobile App Access Management Secure Mobile Gateway
Access Management
LDAP Storage/ Virtual/ Meta Directory
Device Store
Directory Services
System Management and Monitoring
Management
Device and Container Management
Secure Container Mob ile S e cu ri ty
Oracle Mobile Solution
Secure Mobile Workspace - Separate personal and corporate data
Browser
PIM
(email, calendar, contacts, tasks, notes) Doc Editor App Catalog File Manager Secure Intranet Secure Mail Secure Files App Distribution
Secure Apps Enterprise Apps
Data Leakage Control Policy Enforcement Authentication/SSO Encryption in Transit Encryption at Rest
Oracle Mobile Security Solution
Complete Protection of Enterprise Information on Mobile Devices
• Secure, touch-enabled enterprise workspace for iOS and Android
• Trusted workspace for enterprise secure mail, browser, file manager, in-house or 3rd party apps
• Single sign-on just like from your desktop
• No restrictions or controls over personal apps or data
• Increase productivity for mobile workers
• Data leaking control by policy to restrict or allow email, copy/paste, sharing
• Isolate enterprise data access from personal data access
• Manage application and data lifecycle to ensure users only have access to authorized data
• Manage user credential lifecycle
• Deployment options include on-premise or in the cloud
Preserve User Experience
Enable Enterprise Security and Control
Data Leakage Control
Policy Enforcement Authentication
Encryption in Transit Encryption at Rest
Oracle Mobile Security Suite
Secure BOTH containerized and non-containerized apps
Corporate DMZ Corporate Network
Webgate / OHS
Oracle API Gateway
OAM Protected Resources
SOAP/REST and Legacy Web Services
Oracle Access Manager With Mobile & Social
OUD Oracle Adaptive Access / Oracle Mobile Access Server Oracle Mobile Agent Apps
Oracle Mobile Security Admin Console AppTunnel Active Directory Consumer Apps Containerized Apps Oracle Mobile Agent
Mobile
Security Suite
Separately Managing Corporate And Personal Apps/Data On Mobile Devices
Extending Enterprise Identity Services To
Enable Mobile Security with Consistent Policies
Seamless Single Sign-on For Bespoke Applications On Mobile Devices
Reduce Costs, Reduced Risks And Increased Agility With Platform Approach
Join the Community
Twitter twitter.com/OracleIDM Facebook facebook.com/OracleSecurity Oracle Blogs Blogs.oracle.com/OracleIDMOracle IdM Website