CCSK · Question #137
CCM: A hypothetical start-up company called "IT4Sure" provides a cloud based IT management solution. They are growing rapidly and have some security measures in place but the employees are still…
The correct answer is E. All of the above. A complete MDM policy must address all baseline protection areas simultaneously, as each control targets a distinct threat vector that the others do not cover.
Question
CCM: A hypothetical start-up company called "IT4Sure" provides a cloud based IT management solution. They are growing rapidly and have some security measures in place but the employees are still using their personal mobile devices for storing and communicating company confidential information. So they decide to provide the employees with company mobile devices and implement a Mobile Device Management policy. Two months later, a customer wants to review IT4Sure's mobile device security practices. Which of the following basic protection measures should the client look for in the company's Mobile Device Management policy?
Options
- ARegistration of mobile devices
- BRequirements for physical protection
- CRequirements for mobile device software versions and for applying patches
- DMalware protection
- EAll of the above
How the community answered
(35 responses)- A3% (1)
- B11% (4)
- C6% (2)
- D3% (1)
- E77% (27)
Why each option
A complete MDM policy must address all baseline protection areas simultaneously, as each control targets a distinct threat vector that the others do not cover.
Registration alone tracks devices but provides no protection against malware infection, software vulnerabilities, or physical theft of an already-registered device.
Physical protection requirements address only loss or theft scenarios and do not mitigate logical threats such as malware or exploitation of unpatched software.
Patch and software version controls reduce vulnerability exposure but omit physical security requirements, device registration tracking, and malware defense.
Malware protection addresses only one threat category and leaves devices exposed to risks from unpatched vulnerabilities, physical theft, and unregistered unauthorized devices.
All listed measures are recognized baseline MDM controls per the CSA Cloud Controls Matrix: device registration ensures only authorized devices access company data, physical protection requirements guard against theft and loss, software version and patch requirements close known vulnerabilities, and malware protection defends against malicious software - each addressing a separate risk layer that a comprehensive MDM policy must cover.
Concept tested: MDM policy baseline controls per CSA CCM
Source: https://cloudsecurityalliance.org/research/cloud-controls-matrix/
Topics
Community Discussion
No community discussion yet for this question.