Mobile Data Security Policy Plug-In
The Trellia Data Security Policy Plug-In enables IT to set mobile access polices that ensure mobile workers are always securely connected when outside the office. It allows IT to group networks into a "trusted list" to which users can connect and assign network specific security policies to each trusted network.
The core capabilities of the Trellia Data Security Policy Plug-In are:
| Policy Group | Description |
|---|---|
| Trusted Access Networks | Allows IT to control what networks the mobile workers are allowed to access. Through network white-listing/black-listing, IT can allow certain networks and dis-allow others. The solution can discriminate between sanctioned LAN, Wi-Fi and 3G, and location: Office, Home, Public. |
| Security-based network selection (network prioritization) | Allows IT to set, automate and enforce security-based prioritization of network selection to ensure that mobile workers always use the most secure network available in a given location. |
| VPN Enforcement | Allows IT to set, automate and enforce policies around how and when the corporate VPN must be used. In combination with the network trusted list, VPN policy is applied to each network in the list. For example, IT may require that the VPN be enforced on all public networks or only over all public Wi-Fi. Enforcement of the VPN implies enforcing existing corporate VPNs on networks to secure data being transmitted and ensure all traffic goes through the corporate infrastructure, to monitor and apply firewalls, deny access, etc. to specific sites and applications not allowed by the Client's corporate standards. |
| Network Bridging Prevention | Ability to ensure (enforce) that only one network is active at a time. The MPM agent will disable connectivity capability on all other network devices while one connection is active. For example Wi-Fi & 3G radios are turned off when using LAN. |
| Proxy Management | Ability to configure proxy settings associated to different networks according to network location (in-office or out-of-office). |
| Corporate Identity Management | Configuration of solution with the Enterprise's corporate identity, logo. This provides an extra layer of security as mobile workers would be reluctant to try to change corporate policies because of the repercussions. |
| Software Compromise Management | Capacity to block all traffic on device if software is tampered with by end-user against corporate policies. |