Last week I gave a talk at Victor Medina's excellent MILOfest conference about How to Secure Your Mac Law Firm. In preparing for the talk, I developed the following set of best practices that any lawyer using Apple devices should employ to help protect their law firm's data:

Securing Your Desktops/Laptops

  • Upgrade to OS X Lion and enable FileVault 2 for full disk encryption. Read more about FileVault 2 and Lion here.
  • Enable the off-by-default firewall.
  • Set your screen saver / lock screen to activate after 5 or fewer minutes of activity.
  • Disable automatic login.
  • Enable Find my Mac so you can geolocate your device and/or remotely wipe it if necessary.

Securing Your iPhone / iPad

  • Activate the passcode-based lock screen
  • Consider enabling complex passphrases for the lock screen
  • Consider enabling automatic data wipe on your device is passphrase is entered 10 times incorrectly
  • Enable Find my iPhone / Find my iPad so you can geolocate your device and/or remotely wipe it if necessary.

Securing The Cloud

  • Employ a password manager such as 1Password to securely generate and manage your various web site passwords. More on the risks of weak passwords here.
  • Consider using an encryption tool such as TrueCrypt to protect especially sensitive data you're storing in the cloud. Note that full disk encryption does not automatically encrypt data you are storing in the cloud.
  • Dropbox continues to be wildly popular among lawyers despite their various security- and privacy-related failings. Consider using a tool such as SecretSync to encrypt and lock-down your especially sensitive Dropbox data.

This list isn't by any means exhaustive, but it provides a solid foundation for the security of your Mac, iPhone, iPad and cloud-based data. Let me know of any other tips you might have in the comments!

Jack Newton is co-founder and President of Clio, a leading provider of cloud-based practice management software. Jack writes frequently on the security, ethical, and practical aspects of cloud computing, and has spoken at CLE seminars across Canada and the U.S. about how practice management systems can be used to help a lawyer practice efficiently, ethically and competently. Jack can be reached at jack@goclio.com.
[click on the author's name for more information]

up

One Comment on “Securing Your Apple Devices”

  1. William L. Wilson says:

    SpiderOak is a more secure alternative to Dropbox, but it may not integrate as nicely with other apps as Dropbox does. It can be worth looking at.

Make a comment:

Note that some comments may be moderated. If you have not had an approved comment here before, your comment will be held for approval. We are glad to publish comments that address issues raised in the post or other comments on it and that contribute to a fruitful discussion. We do not publish comments that seek to promote commercial products, that make personal attacks, or that seek personal legal advice.

Although we do not require it, we ask that in making a comment you use your full name. You must supply a valid email address, which will not appear with your comment.

 

SlawTips      

SlawTips Cash Flow Reports – Part 2
Thursday, May 24

This is the second in a series of ten tips dealing with cash flow reports and cash flow management. Gregory Nunn once said: “Never underestimate the value of cold cash.”… »»

Practice

SlawTips United Nations Documents
Wednesday, May 23

Today’s Tip: Monitor UN documents with RSS Since I last looked, the United Nations Documents site has a new look and feel. For what the site is trying to deliver, … »»

Research

SlawTips Updated Version of Great Social Media Guide for Lawyers Released
Wednesday, May 23

Last spring, Meritas’ Leadership Institute released a Social Media Guide for Lawyers. This helpful resource provided lawyers with an overview of the three main social media tools — LinkedIn, Faceb. […] »»

Technology

noted on Slaw    

MLB Selected Case Summaries    

These summaries of selected recent cases are provided each week to Slaw by Maritime Law Book.
More information.

  • Aliens - Exclusion and expulsion - Power to detain and deport - Minister’s certificate - Review - Evidence

    In 2002, Harkat was detained pursuant to a ministerial security certificate issued under the Immigration and Refugee Protection Act (IRPA) as a person inadmissible to Canada on grounds ...

  • Contracts - Formation of contract - Signing - Electronic signature

    The plaintiff expressed an interest in purchasing the defendant’s (vendor’s) condo. The parties agreed to carry on their discussions through e-mail. Following an exchange of e-mails, the plaintiff claimed that the defendant was contractually bound to ...

  • Barristers and Solicitors - Relationship with client - Confidential communications - General

    The petitioner was a Receiver appointed in March 2009 by a California court over the assets of GJB Enterprises Inc. (a “Ponzi scheme”) and its principals, the Berkes (the GJB parties). The court ordered ...

  • Practice - Costs - Funding before judgment - When interim or advance costs available

    The plaintiffs were “direct to home” satellite based subscription program providers. Rex and other defendants offered “grey market” services to Canadian residents to facilitate the unauthorized reception in Canada of the plaintiffs’ ...

TalkLaw/ParLoi    

This is a listing of a few upcoming events in Canada of interest to lawyers, law students, legal librarians, and others involved in the practice of law.

Clicking on any event in the list below will give you access to more information and to links allowing you to see the full entry and to add the event to your own calendar.

Click this link for a fuller version of the TalkLaw/ParLoi calendar of events and for instructions as to how to add events and calendars to your own calendar.