About this program
Mobile devices accessing corporate data should be managed. Quick audit on enrolment, posture and wipe capability.
Risks addressed
- High Lost phone with cached mailbox / OneDrive data
- High Unmanaged personal device accessing corporate apps
- High No way to wipe corporate data on offboarding
Controls (6)
-
All corporate phones enrolled in MDM
HighThis control requires that all corporate-issued mobile phones are enrolled in a Mobile Device Management (MDM) platform before being deployed to employees. The MDM system enforces security policies including passcode requirements, encryption, remote wipe capabilities, application whitelisting/blacklisting, and configuration baselines.…
How to test + evidence
Testing procedure: Compare MDM roster against HR + mobile carrier list.
Evidence to collect: MDM roster + delta.
-
Conditional access blocks unenrolled devices
HighThis control enforces conditional access policies that prevent devices not enrolled in the organization's mobile device management (MDM) or unified endpoint management (UEM) platform from accessing corporate resources such as email, file shares, or SaaS applications. When a user attempts…
How to test + evidence
Testing procedure: Tier-1 apps require compliant device claim from MDM.
Evidence to collect: CA policy export.
-
Encryption + passcode enforced
HighThis control requires that mobile devices and endpoints accessing organizational data enforce both encryption at rest and a passcode or biometric lock. Encryption protects data confidentiality if a device is lost or stolen, while passcode enforcement prevents unauthorized physical access.…
How to test + evidence
Testing procedure: MDM profile requires device PIN, biometrics, disk encryption.
Evidence to collect: MDM compliance policy.
-
Remote wipe capability tested
HighRemote wipe capability testing verifies that organizations can remotely erase all data from lost, stolen, or compromised mobile devices and endpoints to prevent unauthorized data access. This control requires documented testing procedures that simulate real-world scenarios, including testing across device…
How to test + evidence
Testing procedure: Documented test of remote-wipe on a sample device within last 12 months.
Evidence to collect: Wipe test report.
-
OS version policy + non-compliant remediation
MediumThis control establishes and enforces a formally documented policy defining minimum acceptable operating system versions across the enterprise, coupled with a structured remediation workflow for devices running non-compliant versions. The policy typically specifies version baselines, patch currency thresholds, and exceptions…
How to test + evidence
Testing procedure: Devices >2 major versions behind are non-compliant and pushed to update.
Evidence to collect: Compliance report.
-
Containerised work profile (BYOD)
MediumContainerised work profiles (also known as work profile containers or managed profiles) enforce logical separation on personally-owned mobile devices by isolating enterprise applications, data, and credentials into a separate encrypted partition or profile. This approach enables BYOD policies by allowing…
How to test + evidence
Testing procedure: Personal devices use work profile; corporate data isolated.
Evidence to collect: BYOD config.