nerdexam
Isaca

CRISC · Question #14

An organization has an approved bring your own device (BYOD) policy. Which of the following would BEST mitigate the security risk associated with the inappropriate use of enterprise applications on th

The correct answer is C. Implement BYOD mobile device management (MDM) controls.. Implementing Mobile Device Management (MDM) controls is the most effective way to mitigate security risks from inappropriate use of enterprise applications on BYOD devices.

Submitted by jakub_pl· Apr 18, 2026Risk Response and Reporting

Question

An organization has an approved bring your own device (BYOD) policy. Which of the following would BEST mitigate the security risk associated with the inappropriate use of enterprise applications on the devices?

Options

  • APeriodically review application on BYOD devices
  • BInclude BYOD in organizational awareness programs
  • CImplement BYOD mobile device management (MDM) controls.
  • DEnable a remote wee capability for BYOD devices

How the community answered

(38 responses)
  • A
    8% (3)
  • B
    11% (4)
  • C
    79% (30)
  • D
    3% (1)

Why each option

Implementing Mobile Device Management (MDM) controls is the most effective way to mitigate security risks from inappropriate use of enterprise applications on BYOD devices.

APeriodically review application on BYOD devices

Periodically reviewing applications on BYOD devices is reactive and less effective than proactive technical controls, as it relies on detection rather than prevention and enforcement.

BInclude BYOD in organizational awareness programs

Including BYOD in organizational awareness programs educates users but does not provide the technical enforcement needed to prevent or mitigate inappropriate application use effectively.

CImplement BYOD mobile device management (MDM) controls.Correct

Implementing BYOD mobile device management (MDM) controls provides robust technical mechanisms to enforce security policies, containerize enterprise applications and data, and remotely wipe or control access in case of non-compliance or device loss. This directly addresses the risk of inappropriate use by applying granular controls over how applications and data are accessed and managed on personal devices.

DEnable a remote wee capability for BYOD devices

Enabling a remote wipe capability for BYOD devices is a reactive control for data loss or device theft, but it does not prevent the inappropriate use of applications during normal operation.

Concept tested: BYOD Security Controls (MDM)

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.1800-4.pdf

Topics

#BYOD security#Mobile Device Management (MDM)#Risk mitigation#Application security

Community Discussion

No community discussion yet for this question.

Full CRISC Practice