CRISC · Question #14
An organization has an approved bring your own device (BYOD) policy. Which of the following would BEST mitigate the security risk associated with the inappropriate use of enterprise applications on th
The correct answer is C. Implement BYOD mobile device management (MDM) controls.. Implementing Mobile Device Management (MDM) controls is the most effective way to mitigate security risks from inappropriate use of enterprise applications on BYOD devices.
Question
An organization has an approved bring your own device (BYOD) policy. Which of the following would BEST mitigate the security risk associated with the inappropriate use of enterprise applications on the devices?
Options
- APeriodically review application on BYOD devices
- BInclude BYOD in organizational awareness programs
- CImplement BYOD mobile device management (MDM) controls.
- DEnable a remote wee capability for BYOD devices
How the community answered
(38 responses)- A8% (3)
- B11% (4)
- C79% (30)
- D3% (1)
Why each option
Implementing Mobile Device Management (MDM) controls is the most effective way to mitigate security risks from inappropriate use of enterprise applications on BYOD devices.
Periodically reviewing applications on BYOD devices is reactive and less effective than proactive technical controls, as it relies on detection rather than prevention and enforcement.
Including BYOD in organizational awareness programs educates users but does not provide the technical enforcement needed to prevent or mitigate inappropriate application use effectively.
Implementing BYOD mobile device management (MDM) controls provides robust technical mechanisms to enforce security policies, containerize enterprise applications and data, and remotely wipe or control access in case of non-compliance or device loss. This directly addresses the risk of inappropriate use by applying granular controls over how applications and data are accessed and managed on personal devices.
Enabling a remote wipe capability for BYOD devices is a reactive control for data loss or device theft, but it does not prevent the inappropriate use of applications during normal operation.
Concept tested: BYOD Security Controls (MDM)
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.1800-4.pdf
Topics
Community Discussion
No community discussion yet for this question.