HomeTechnologyA CISO’s perspective on a TikTok ban and what it means for...

A CISO’s perspective on a TikTok ban and what it means for enterprises 


Be a part of high executives in San Francisco on July 11-12, to listen to how leaders are integrating and optimizing AI investments for achievement. Be taught Extra


The federal authorities is contemplating pushing an outright ban on the video-sharing app TikTok throughout the U.S., simply weeks after banning the app from all U.S. authorities units. Citing knowledge privateness considerations stemming from TikTok’s mother or father firm, the Chinese language agency ByteDance, officers have made it clear that they imagine the app may very well be used to spy on People’ private info and ship that knowledge on to the Chinese language authorities, which is thought for cyber-theft of IR, commerce secrets and techniques and different proprietary info from Western firms to advance its personal nationwide safety priorities.

Contemplating what to do about TikTok

However for companies that use TikTok for advertising or make use of any of the 150 million People who’ve the app, what’s to be finished? The reply, for now, lies in following primary safety hygiene practices for all data-collecting apps, not simply TikTok. 

The truth is that it doesn’t matter what TikTok’s affiliation with the Chinese language authorities is, it’s not the one app that’s able to actively farming person knowledge. Snapchat, Google and Meta all make the most of person knowledge to extra granularly goal advertisements and perceive person habits.

No firm is resistant to cyber-breaches and knowledge theft, a lot of that extremely private knowledge may be probably uncovered by an adversary. TikTok does knowledge assortment on a big scale due to the dimensions of its person base and present recognition, however usually, when you’re not paying for the app or service, it’s utilizing your knowledge to become profitable.

Occasion

Rework 2023

Be a part of us in San Francisco on July 11-12, the place high executives will share how they’ve built-in and optimized AI investments for achievement and prevented widespread pitfalls.

 


Register Now

After all, the rationale we — and Congress — are having this dialogue proper now could be that, in contrast to any of these social media firms, TikTok is owned by a international firm affiliated with China. Though we must be cautious when utilizing social media platforms, irrespective of who owns them, TikTok is amassing huge quantities of knowledge from American customers, and we don’t know what that knowledge is getting used for or if a international authorities has entry to the information.

Is BYOD best for you?

For this reason enterprises that permit staff to convey their very own units into the workplace or conduct work on them — “BYOD” — ought to instantly reevaluate their insurance policies. Extra particularly, they need to ensure that they’re conscious of the varieties of firm info staff have on their private units, and take the mandatory measures to make sure that info is separated from the remainder of the apps on these units. 

There are controls that organizations can implement to make sure that delicate firm info isn’t being collected by any sort of app, TikTok or not. However usually, employers can’t concern an outright ban on staff downloading no matter app they’d like onto a private system. Organizations can have acceptable use insurance policies (AUPs) that administratively require staff to not use social media, together with TikTok, whereas on firm time, however that’s not a ban on having the app on the system. It additionally doesn’t forestall the app from amassing info, which it does on a regular basis.

Technical options that may be put in on private units to forestall delicate work info from being collected by apps, or, for instance, downloading delicate paperwork from e-mail, should be arrange, maintained and monitored. That may be costly and time-consuming, and it requires a corporation to have good knowledge dealing with practices in place already, together with classifying info and property and having visibility into how that info is processed and used on staff’ private units. Enterprise safety leaders ought to perceive precisely what info they should defend to make higher threat choices about how that info is dealt with.

What about work telephones?

The choice route for enterprise involved about TikTok’s knowledge assortment practices is to concern its personal units to staff, pre-loaded with safety controls that forestall unknown or unauthorized functions from being downloaded. If the group owns the system, they will management precisely what’s allowed to be finished and downloaded onto the system to make sure correct safety protocols are being adopted.

However issuing firm units will also be costly, and enterprises contemplating the choice to buy laptops or telephones for workers should consider comfort, enterprise imperatives and knowledge safety threat. 

The particular dangers highlighted by the TikTok concern will not be new however have reached a brand new degree of visibility as a result of app’s unimaginable recognition. Whereas Congress deliberates on banning the app, enterprise safety leaders know that the tough concern of knowledge privateness and worker property doesn’t finish with TikTok, and discovering new options can be crucial as different data-collecting apps rise in utilization. There’s by no means been a greater time for these leaders to convey safety to the entrance and middle of their organizations’ priorities.

Adam Marrè is Chief Data Safety Officer at Arctic Wolf.

DataDecisionMakers

Welcome to the VentureBeat group!

DataDecisionMakers is the place specialists, together with the technical folks doing knowledge work, can share data-related insights and innovation.

If you wish to examine cutting-edge concepts and up-to-date info, greatest practices, and the way forward for knowledge and knowledge tech, be a part of us at DataDecisionMakers.

You may even contemplate contributing an article of your personal!

Learn Extra From DataDecisionMakers

RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Most Popular

Recent Comments