In the frenzy to build and deploy mobile apps, on the iPhone and on Android in particular, security is often ignored.
This is a big concern, especially for those who are interested in the enterprise applications development or Mobile Enterprise Application Platform (MEAP) space. In many ways this is analogous to the early days of the web, where the emphasis was to deploy at all costs. Additionally, the app market emerged in 2007 with a rapidly growing range of gaming and funky consumer apps, where security was low priority.
One of the main concerns cited by business and enterprise in adopting mobile app strategies is security. While businesses have slowly overcome their fears of security in the cloud, they are now faced with the dilemma of protecting their business assets in the mobile and social space.
Successful design, deployment, delivery and management of mobile enterprise apps should be underpinned by a comprehensive security strategy that incorporates secure connectivity, authentication, access control, and data confidentiality. In addition, well-behaved enterprise apps need to have higher level reporting facilities such as auditing, logging and monitoring that in turn enable higher-level security checks, such as suspicious patterns of usage. A cloud-based solution for enterprise mobility addresses both the security concerns of the apps on the device and of the service/data in the cloud.
The key security features to consider in the mobile enterprise app space are:
Secure Connectivity
All communication between users, apps and servers can be fully encrypted using SSL to negotiate 256-bit AES key exchange. The development platform should support secure access to private APIs via Virtual Private Networks (VPNs) connecting our enterprise customers.
Authentication
The development platform should support both developer and app-level authentication, enabling secure identification and fine-grained control for developers and enterprise customers alike. All authentication criteria should be encrypted and subject to enforced strength and reminders. True secure authentication needs to go beyond the assumption that possession of a device is sufficient for authentication.
Access Control & Authorization
The use of role-based access controls and authorization enable employee, customer and partner-level access to be provisioned and managed in the cloud. Enterprise customers can be segregated using advanced virtualization technologies, preventing unauthorized access.
Downtime Protection
Use of cloud technology provides a high level of resilience and provides several layers of redundancy. Employing innovative caching and business logic engineered to minimize downtime, provides ultimate protection.
Security Ethos
Besides the implementation of security technologies, a strong security ethos is essential in serving the enterprise app market. Continually improving processes, controls and procedures and commitment to regular security awareness training, helps govern all aspects of a company’s operations and aid in security and risk management.
As the enterprise app space takes off, developers are faced with a new set of rules in building and deploying secure and sophisticated business apps.
FeedHenry is leading the way in providing integrated security for its cloud-based solution for enterprise mobility. Our commitment to security makes the FeedHenry Astum platform the secure option for developers and enterprises alike.

For more information or a demo please visit us at www.feedhenry.com