CAS-003 · Question #628
A new corporate policy requires that all employees have access to corporate resources on personal mobile devices. The information assurance manager is concerned about the potential for inadvertent…
The correct answer is A. Place corporate applications in a container. Containerization on personal mobile devices isolates corporate data from personal data, protecting against loss-related disclosure while respecting user privacy concerns.
Question
A new corporate policy requires that all employees have access to corporate resources on personal mobile devices. The information assurance manager is concerned about the potential for inadvertent and malicious data disclosure if a device is lost, while users are concerned about corporate overreach. Which of the following controls would address these concerns and should be reflected in the company's mobile device policy?
Options
- APlace corporate applications in a container
- BEnable geolocation on all devices
- Cinstall remote wiping capabilities
- DEnsure all company communications use a VPN
How the community answered
(55 responses)- A89% (49)
- B2% (1)
- C4% (2)
- D5% (3)
Why each option
Containerization on personal mobile devices isolates corporate data from personal data, protecting against loss-related disclosure while respecting user privacy concerns.
Placing corporate applications in a container via MAM or MDM containerization creates an encrypted, isolated partition for corporate data that can be selectively wiped without affecting the user's personal content if the device is lost. This directly addresses the information assurance manager's concern about data disclosure because only the container and its contents are exposed in a loss scenario. It also resolves user concerns about corporate overreach because the company cannot access or wipe personal photos, apps, or communications stored outside the container.
Geolocation helps locate a missing device but does not prevent unauthorized access to corporate data stored on that device.
Remote wiping erases the entire device including all personal data, which intensifies rather than resolves user concerns about corporate overreach into personal information.
A VPN secures corporate data in transit between the device and internal systems but provides no protection for data already stored locally on the device if it is lost or stolen.
Concept tested: Mobile device containerization for BYOD data protection
Source: https://csrc.nist.gov/pubs/sp/800/124/r2/final
Topics
Community Discussion
No community discussion yet for this question.