CAS-002 · Question #778
A company has issued a new mobile device policy permitting BYOD and company-issued devices. The company-issued device has a managed middleware client that restricts the applications allowed on…
The correct answer is B. IT governance. Using formal policies, a standardized middleware client, and published memoranda to govern both company-issued and BYOD devices according to defined security and business requirements describes IT governance.
Question
A company has issued a new mobile device policy permitting BYOD and company-issued devices. The company-issued device has a managed middleware client that restricts the applications allowed on company devices and provides those that are approved. The middleware client provides configuration standardization for both company owned and BYOD to secure data and communication to the device according to industry best practices. The policy states that, "BYOD clients must meet the company's infrastructure requirements to permit a connection." The company also issues a memorandum separate from the policy, which provides instructions for the purchase, installation, and use of the middleware client on BYOD. Which of the following is being described?
Options
- AAsset management
- BIT governance
- CChange management
- DTransference of risk
How the community answered
(22 responses)- A14% (3)
- B77% (17)
- C5% (1)
- D5% (1)
Why each option
Using formal policies, a standardized middleware client, and published memoranda to govern both company-issued and BYOD devices according to defined security and business requirements describes IT governance.
Asset management focuses on tracking and maintaining an inventory of IT assets, not on establishing policy frameworks that control device usage, application approval, and data security.
IT governance encompasses the policies, frameworks, and controls an organization uses to ensure IT resources are aligned with business objectives and operated to defined standards. The scenario illustrates this through a formal policy, a middleware client enforcing approved configurations and data security, and a separate memorandum providing operational guidance - all hallmarks of a governance structure applied to mobile device management.
Change management addresses the process for requesting, reviewing, and approving modifications to IT systems, not the ongoing governance of device policies and configuration standards.
Transference of risk involves shifting risk liability to a third party such as through insurance or vendor contracts, which is not occurring in this scenario.
Concept tested: IT governance framework applied to mobile device management
Topics
Community Discussion
No community discussion yet for this question.