NASA will be implementing the IT security measures described in the attached memo this week. I am sending this note to all of HEOMD so that you have a clearer understanding of what this means to you and any personal devices you connect to NASA's email / NOMAD ActiveSync service, and so you aren't taken by surprise if or when your personal device starts asking you to do things, like setting an unlock code.
- ActiveSync is the primary means of connecting a device such as an iPhone, iPad, Android or other type of device to NOMAD so that you can access your NASA email on the device. ActiveSync has the ability to 'push' certain policies to any device that uses ActiveSync to connect to NASA's email system. When you configure and connect your device to NASA's email system, though you may select "Microsoft Exchange" as the connectivity option, ActiveSync is the actual service and protocol that does the work to create and maintain the connection and to get and send your email.
- Understand that NASA has not banned use of your own personal devices to access NOMAD / NASA email, though NASA does have the authority and ability to do so. The phrase "Bring Your Own Device", or "BYOD" is used to denote such devices that are not issued by NASA or the Government, but which are instead personally owned.
- For some odd reason, there are a significant number of non-NASA issued and non-Government devices that are accessing NOMAD via ActiveSync. Even more odd is that the number of new non-NASA devices that connect to NOMAD increases significantly in the days and weeks immediately after Christmas. (Yeah, I know why, but I want to add a sense of mystery here).
- Accessing email and other NASA information that is not for public release via personal devices does pose some risk to NASA data; implementing certain security precautions on a device helps reduce that risk significantly should that device be lost or stolen, regardless of whether it is a government-owned or personally owned device. Connecting to NOMAD via a personal device is a privilege, not a right. With the privilege come some restrictions, and some risks. By connecting your personal device to NOMAD or the NASA internal network, you are implicitly accepting those restrictions and risks.
- The attached policy is a compromise between allowing use of personal devices and banning personal devices entirely from connecting to NOMAD. The goal here is to ensure that some minimum security is enabled on any device that NASA does not manage and that is connecting to NOMAD.
- The policies that NASA's NOMAD / ActiveSync server will be pushing to your personal device at a minimum will enable several capabilities on your device to improve its security. First, the policies will ensure that a PIN or passcode is set and that must be used to unlock the device so that if it is lost or stolen, it will not be easy for an unauthorized individual to gain access to your email. Second, where a device can implement this, the policies pushed will set the device to be auto-wiped if there are more than 10 failed attempts to unlock the device; this is to reduce the likelihood of a brute-force guessing of the unlock code. Third, the policies will ensure that encryption capabilities for data-at-rest are turned on for your personal device.
- Each device is different, so I'm not certain what the effects will be on every type of device. I do know that for iOS devices such as iPhones or iPads the changes won't be too onerous. iOS uses data-at-rest encryption by default, so that is already turned on. If you do not have an unlock code set on your iOS device, once the policies are pushed, you will be prompted to set at minimum a 4 digit unlock code, and your device will auto-lock after 15 minutes being idle. Also, failure to input the correct unlock code after 10 tries will auto-wipe the device. Also, the option is there for a remote wipe of your device from ActiveSync, but that option will not be used without the device owner's direct permission and by their request. Again, I am not certain what you will see or how other devices will react to the policies being pushed.
- Contrary to the nonsense you've been reading at nasawatch or elsewhere, NASA does not obtain control of your personal device; NASA cannot remotely read the contents of your device; NASA does not know your unlock code; and NASA will not remotely trigger a wipe of your personal device without your direct authorization to do so. We are NASA, not NSA. Don't drop the first 'A', eh?
Follow this link:
NASA HEOMD Internal Memo on Personnal Electronic Devices
- 2D Laser Profiling Scanner for Detecting Targets [Last Updated On: November 8th, 2009] [Originally Added On: November 8th, 2009]
- NASA Energy Concept Could Harness the Power of Ocean Waves [Last Updated On: November 8th, 2009] [Originally Added On: November 8th, 2009]
- Data Acquisition Modules [Last Updated On: November 8th, 2009] [Originally Added On: November 8th, 2009]
- Dr. Scott Barthelmy, Research Scientist, Laboratory for High Energy Astrophysics, Goddard Space Flight Center, Greenbelt, MD [Last Updated On: November 8th, 2009] [Originally Added On: November 8th, 2009]
- Laser Tracker Ensures Accurate Alignment of Ares I Components [Last Updated On: November 8th, 2009] [Originally Added On: November 8th, 2009]
- Dual Cryogenic Capacitive Density Sensor [Last Updated On: November 8th, 2009] [Originally Added On: November 8th, 2009]
- Advanced Technologies Will Help Hubble Yield More Remarkable Discoveries [Last Updated On: November 8th, 2009] [Originally Added On: November 8th, 2009]
- Dr. Gerard Holzmann, Senior Research Scientist at the Laboratory for Reliable Software, NASA’s Jet Propulsion Laboratory [Last Updated On: November 8th, 2009] [Originally Added On: November 8th, 2009]
- NASA Research Will Help Aircraft Avoid Ocean Storms and Turbulence [Last Updated On: November 8th, 2009] [Originally Added On: November 8th, 2009]
- NASA Awards 2008 Software of the Year [Last Updated On: November 8th, 2009] [Originally Added On: November 8th, 2009]
- Here Come The Tricorders - Update [Last Updated On: November 8th, 2009] [Originally Added On: November 8th, 2009]
- China's View on Space [Last Updated On: November 8th, 2009] [Originally Added On: November 8th, 2009]
- Milsat Coordination and Tracking Issues [Last Updated On: November 8th, 2009] [Originally Added On: November 8th, 2009]
- Trash Talking and End Runs at NASA HQ [Last Updated On: November 8th, 2009] [Originally Added On: November 8th, 2009]
- Ares 1-Y is Toast [Last Updated On: November 8th, 2009] [Originally Added On: November 8th, 2009]
- Beyond Augustine [Last Updated On: November 8th, 2009] [Originally Added On: November 8th, 2009]
- Analyzing LCROSS' Plume [Last Updated On: November 8th, 2009] [Originally Added On: November 8th, 2009]
- Live Event: NASA-Sponsored Power Beaming Challenge [Last Updated On: November 8th, 2009] [Originally Added On: November 8th, 2009]
- JSC Wants To Build a Replicator [Last Updated On: November 8th, 2009] [Originally Added On: November 8th, 2009]
- USA: Looking For Ways To Hang On [Last Updated On: November 8th, 2009] [Originally Added On: November 8th, 2009]
- Lunar Lander Challenge Prizes Awarded [Last Updated On: November 8th, 2009] [Originally Added On: November 8th, 2009]
- Senate Votes To Restore NASA Budget Cuts [Last Updated On: November 8th, 2009] [Originally Added On: November 8th, 2009]
- New FAA Regs for Commercial Reentry [Last Updated On: November 8th, 2009] [Originally Added On: November 8th, 2009]
- TEDxNASA: An Invitation-Only NASA Meeting - Unless You Are Lucky [Last Updated On: November 8th, 2009] [Originally Added On: November 8th, 2009]
- Close Call For Courtney Stadd [Last Updated On: November 8th, 2009] [Originally Added On: November 8th, 2009]
- Space: A Waste? [Last Updated On: November 8th, 2009] [Originally Added On: November 8th, 2009]
- Making NASA Cool [Last Updated On: November 8th, 2009] [Originally Added On: November 8th, 2009]
- Engaging JSC’s Next Gen: A Leadership Analysis [Last Updated On: November 8th, 2009] [Originally Added On: November 8th, 2009]
- Dumpster Diving for Rockets [Last Updated On: November 8th, 2009] [Originally Added On: November 8th, 2009]
- TEDx NASA [Last Updated On: November 8th, 2009] [Originally Added On: November 8th, 2009]
- Reflections On a Business Trip in Huntsville [Last Updated On: November 8th, 2009] [Originally Added On: November 8th, 2009]
- Staying the Course [Last Updated On: November 8th, 2009] [Originally Added On: November 8th, 2009]
- The Economics of Space [Last Updated On: November 8th, 2009] [Originally Added On: November 8th, 2009]
- Ideas at Work [Last Updated On: November 8th, 2009] [Originally Added On: November 8th, 2009]
- Blah Blah Blah - Why We Should Care About Social Media [Last Updated On: November 8th, 2009] [Originally Added On: November 8th, 2009]
- Will White House Speak Soon About NASA? [Last Updated On: December 12th, 2009] [Originally Added On: December 12th, 2009]
- Software Aids Design of Ares V Composite Shroud Structure [Last Updated On: December 13th, 2009] [Originally Added On: December 13th, 2009]
- ASDX Series of silicon pressure sensors [Last Updated On: December 13th, 2009] [Originally Added On: December 13th, 2009]
- Industry Update: Analysis & Simulation Software [Last Updated On: December 13th, 2009] [Originally Added On: December 13th, 2009]
- Battery Will Provide Backup Power for Space Shuttles [Last Updated On: December 13th, 2009] [Originally Added On: December 13th, 2009]
- NASA Employee Claims To Have Witnessed Hijacking Planning [Last Updated On: December 13th, 2009] [Originally Added On: December 13th, 2009]
- Big Party in The Mojave Tonight [Last Updated On: December 13th, 2009] [Originally Added On: December 13th, 2009]
- Looking at Boulders on the Moon [Last Updated On: December 13th, 2009] [Originally Added On: December 13th, 2009]
- SpaceBook Featured by White House [Last Updated On: December 13th, 2009] [Originally Added On: December 13th, 2009]
- New Ways to Use Constellation Stuff [Last Updated On: December 13th, 2009] [Originally Added On: December 13th, 2009]
- LaRC internal Poll Update [Last Updated On: December 13th, 2009] [Originally Added On: December 13th, 2009]
- Coalition for Space Exploration Does a (Much Needed) Reboot [Last Updated On: December 13th, 2009] [Originally Added On: December 13th, 2009]
- Lunar Orbiter: Comparing Old and New Images [Last Updated On: December 13th, 2009] [Originally Added On: December 13th, 2009]
- Boulder Trails On The Moon [Last Updated On: December 13th, 2009] [Originally Added On: December 13th, 2009]
- Vote for John Grunsfeld - National Geographic Adventurer of the YeAR [Last Updated On: December 13th, 2009] [Originally Added On: December 13th, 2009]
- Charlie Bolden at WIA/AIAA [Last Updated On: December 13th, 2009] [Originally Added On: December 13th, 2009]
- Live Webcast From The Lunar Orbiter Image Recovery Project [Last Updated On: December 13th, 2009] [Originally Added On: December 13th, 2009]
- Big Aerospace Warns of Job Cut Impact [Last Updated On: December 13th, 2009] [Originally Added On: December 13th, 2009]
- The Boulders of Copernicus [Last Updated On: December 13th, 2009] [Originally Added On: December 13th, 2009]
- shame on us [Last Updated On: December 13th, 2009] [Originally Added On: December 13th, 2009]
- 2009 Space Elevator Games [Last Updated On: December 13th, 2009] [Originally Added On: December 13th, 2009]
- Random Hacks of Kindness [Last Updated On: December 13th, 2009] [Originally Added On: December 13th, 2009]
- TEDx NASA Tickets Available to the Public [Last Updated On: December 13th, 2009] [Originally Added On: December 13th, 2009]
- It’s better in person [Last Updated On: December 13th, 2009] [Originally Added On: December 13th, 2009]
- Leading Amidst the Disruptive Innovation Storm [Last Updated On: December 13th, 2009] [Originally Added On: December 13th, 2009]
- Space: What’s NOT to Hope for? [Last Updated On: December 13th, 2009] [Originally Added On: December 13th, 2009]
- Government in the Digital Age [Last Updated On: December 13th, 2009] [Originally Added On: December 13th, 2009]
- SpaceUp – A Space Unconference [Last Updated On: December 13th, 2009] [Originally Added On: December 13th, 2009]
- Starfleet Academy? [Last Updated On: December 13th, 2009] [Originally Added On: December 13th, 2009]
- Crowdsourcing NASA [Last Updated On: December 13th, 2009] [Originally Added On: December 13th, 2009]
- Bringing Home The Bacon [Last Updated On: December 14th, 2009] [Originally Added On: December 14th, 2009]
- Anti-Space Mom with Pro-Space Kids [Last Updated On: December 14th, 2009] [Originally Added On: December 14th, 2009]
- How Quickly We Forget [Last Updated On: December 14th, 2009] [Originally Added On: December 14th, 2009]
- WISE Launch A Success [Last Updated On: December 14th, 2009] [Originally Added On: December 14th, 2009]
- Dynetics Buys Orion Propulsion [Last Updated On: December 15th, 2009] [Originally Added On: December 15th, 2009]
- New NASA Governance Structure Under Development [Last Updated On: December 16th, 2009] [Originally Added On: December 16th, 2009]
- Bolden Meets With Obama on Wednesday [Last Updated On: December 16th, 2009] [Originally Added On: December 16th, 2009]
- MSFC Procurement Doesn't Understand what "Open Source" Means [Last Updated On: December 16th, 2009] [Originally Added On: December 16th, 2009]
- Bolden Meets With Obama [Last Updated On: December 17th, 2009] [Originally Added On: December 17th, 2009]
- Parker Griffith AT MSFC Today [Last Updated On: December 18th, 2009] [Originally Added On: December 18th, 2009]
- Why Your NASA Computer May Not Work Properly [Last Updated On: December 18th, 2009] [Originally Added On: December 18th, 2009]
- Lakes and Fog on Titan [Last Updated On: December 18th, 2009] [Originally Added On: December 18th, 2009]
- Waterworld Found [Last Updated On: December 18th, 2009] [Originally Added On: December 18th, 2009]
- Pandora Could Exist [Last Updated On: December 18th, 2009] [Originally Added On: December 18th, 2009]
- Laurie Leshin Is The New ESMD Deputy AA [Last Updated On: December 18th, 2009] [Originally Added On: December 18th, 2009]