Summer 2015 Planet of the Apps
Total Page:16
File Type:pdf, Size:1020Kb
QUARTERLY VOL. 7 NO. 1 SUMMER 2015 PLANET OF THE APPS Advances in Enterprise Mobile Applications IQT Quarterly is a publication of In-Q-Tel, Inc., the strategic investment firm that serves as a bridge between the U.S. Intelligence Community and venture-backed startup firms on the leading edge of technological innovation. IQT Quarterly advances the situational awareness component of the IQT mission, serving as a platform to debut, discuss, and debate issues of innovation in the areas of overlap between commercial potential and U.S. Intelligence Community needs. For comments or questions regarding IQT or this document, please visit www.iqt.org, write to [email protected], or call 703-248-3000. The views expressed are those of the authors in their personal capacities and do not necessarily reflect the opinion of IQT, their employers, or the Government. ©2015 In-Q-Tel, Inc. This document was prepared by In-Q-Tel, Inc., with Government funding (U.S. Government Contract No. 2014-14031000011). The Government has Government Purpose License Rights in this document. Subject to those rights, the reproduction, display, or distribution of the IQT Quarterly without prior written consent from IQT is prohibited. EDITORIAL IQT Quarterly, published by In-Q-Tel, Inc. Editor-in-Chief: Adam Dove Theme Editor: Isaac Myauo Contributing Editors: Brittany Carambio and Carrie Sessine Design by Lomangino Studio LLC Printed in the United States of America QUARTERLY Identify. Adapt. Deliver. TABLE OF CONTENTS On Our Radar: Mobile Apps are Eating the World 02 By Isaac Myauo A Look Inside: Planet of the Apps 05 How to Secure, Deploy, and Manage Mobile Apps 06 in Highly Secure Settings By Harvey Morrison The Changing Nature of Authentication: 10 Meeting the Needs of Mobile Enterprise Applications By Phillip Dunkelberger Enterprise Mobile Apps: A Promise Unfulfilled 14 By Todd Fryburger Mobility, Operational Tempos, Information Strategies, 20 and the Real-Time Enterprise By Kevin Benedict Situational Awareness and Interoperability Defining 24 Next-Generation Public Safety Mobile Solutions By David Krebs Apps are Now Mission-Critical 29 By Andrew Levy From the Portfolio 33 IQT QUARTERLY SUMMER 2015 Vol. 7 No. 1 01 IQT QUARTERLY ON OUR RADAR Mobile Apps are Eating the World By Isaac Myauo In late 2014, Benedict Evans of Andreessen Horowitz presented “Mobile is Eating the World,” where he provided insights on how mobile technology is redefining the Internet and broader tech industry. Evans cited statistics on how users spend more time using mobile apps than the rest of the Web, how mobile first transforms development and capital requirements, and how mobile technology creates new business opportunities that are the foundation of industry disruption. We saw tremendous growth in mobile in 2014, but the enterprise still faces many challenges. This issue of the IQT Quarterly builds on topics discussed in our summer 2012 edition, “Slide to Unlock: The Challenges of Enterprise Mobility” and focuses on the challenges the enterprise faces after issuing or allowing mobile devices. Mobile technology is a phenomenon that has evolved of complex issues surrounding security, management, over the last few years and is continuously transforming development, time-to-market, cost, performance, and the consumer market. In the enterprise, 2014 saw an user experience that need to be addressed. increased focus on mobility and the importance of apps Security for business. The partnership announced between Apple and IBM to transform enterprise mobility seeks for IT Securing mobile apps is a challenge — breaches and organizations to first easily adopt, use, and support data leaks can be disasters. Bring Your Own Device mobile platforms, and secondly demonstrate the (BYOD) policies elevate this risk for the enterprise. importance of well integrated enterprise apps. Google’s Enterprise mobility management (EMM) solutions announcement and recent release of Android for Work have evolved and are relatively mature in mitigating provides increased management and data separation risks by providing scalable tools to manage the device, for work-approved apps. While corporations have largely force encryption, sandbox apps, and set policies, but IT adopted mobile device management (MDM) solutions departments have lost the degree of control in decision- to secure, manage, and control the device, the mobile making they once had regarding device approval. The operating system (OS) industry has also seen a greater fragmentation of mobile platforms and architectures need and push to focus on security and privacy beyond leads to a diverse attack surface for an adversary. the device in response to the challenges within the Enterprise app developers and IT departments, through mobile IT environment. EMM solutions, may enforce best practices for their apps, but by and large the attack surface remains. The rapid adoption of mobile devices and mobile apps Samsung KNOX and Android for Work reduce this attack by consumers has translated to the enterprise. Users surface for many enterprises, but risks still remain within the enterprise now demand a mobile experience and enterprises need to plan, provide remediation, and that is on par with or better than commercial apps. This enable multiple layers of security. presents app developers and IT organizations with a set 02 Vol. 7 No. 1 Identify. Adapt. Deliver. IQT QUARTERLY Users within the enterprise now demand a mobile experience that is on par with or better than commercial apps. This presents app developers and IT organizations with a set of complex issues surrounding security, management, development, time-to- market, cost, performance, and user experience that need to be addressed. Authentication responsive web design (RWD), cross-platform, and app Mobile authentication is difficult; the username and transformation/porting tools are available and have password approach is insecure. This forces IT to increasingly matured over the last few years. However, impose long, complex passwords that hinder the user each tool has its benefits and drawbacks. IQT recently experience. Commercial apps leave security holes conducted a market survey on mobile app development, by leaving the user logged in. Users expect the same which included comparisons of the various mobile app from their enterprise apps — a clunky authentication development tools on the market today. We found that experience or a too heavily locked down app isn’t likely over the past few years, cross-platform tools have to be well adopted by users. The solution is multi-factor improved to provide better performance and better authentication — something you know (e.g., password/ integration with the mobile platform. We believe that PIN), something you have (e.g., tokens), and who you are the enterprise should choose a cross-platform tool that (e.g., biometrics). Above multi-factor is context: policies provides native or native-like performance and the code to choose the right authentication measures based on should be portable. App transformation/porting tools environmental risks and past behaviors. However, both simplify the porting of legacy desktop applications to IT and developers are challenged with understanding run on a mobile device and are best used to provide the complexities and managing the time and cost of a native-like app that follows business-specific how various biometric and token-based authentication workflows. Moreover, this market survey concludes solutions will integrate with the back end and the app. that it is important for the developer and enterprise to Standards that abstract this complexity and enable the understand the apps they need and choose the right tool enterprise to move beyond passwords to more secure for each project. authentication measures have been developed and are User Experience being standardized. Mobility is about experience. Apps that are overly App Development and Mobilization complex, too restrictive, or perform poorly will quickly The job of a mobile app developer has become lose attention and relevance. Mobile app testing tools increasingly complex. There are a spectrum of mobile that are integrated with the development lifecycle for devices and OSes; from smartphones, tablets, and continuous integration allow developers to optimize wearables to Android, iOS, and Windows Mobile. In the in-app experience before release. But these tools addition, developers need to prioritize the devices and can only capture a subset of real world data points OS to target; they also must struggle to decide which to test against. Other apps and services running legacy applications they need to support for the mobile alongside your app, as well as network, device, and OS workforce. Time-to-market, cost, user experience, and variability are all events that are not easily testable. app performance all factor into these decisions. Native, However, mobile application performance monitoring IQT QUARTERLY SUMMER 2015 Vol. 7 No. 1 03 IQT QUARTERLY (mAPM) tools that continuously report these events at deployment and usage. This ALM framework runtime are accessible, and provide rich data about should be extensible — allowing the enterprise to app performance, app crashes, and user experience. integrate with EMM and other tools within the These tools enable developers to monitor, prioritize, enterprise IT infrastructure. troubleshoot, and trend mobile app performance to These are a few of the many challenges associated accelerate enterprise mobility and engage their users. with