NIST Protect - Mobile Device Management

Mobile Device Management (MDM):

  • MDM enables secure management of laptops, tablets, and mobile phones by ensuring data protection and maintaining compliance with security policies. Here are a few key threats:

1. Unauthorized Access

  • Risk: Devices not managed by MDM may not have proper access controls (e.g., strong passwords, biometrics, multi-factor authentication).
  • Impact: Employees may access sensitive company resources from untrusted or compromised devices.
  • Example: An employee’s personal phone, without enforced MFA or strong passwords, accesses corporate email or VPN, potentially leading to unauthorized access to internal systems.

2. Inconsistent Security Policies

  • Risk: Without MDM, it’s difficult to enforce consistent security policies across all devices, leading to non-compliance with organizational or regulatory requirements.
  • Impact: Security gaps may exist on certain devices, creating vulnerabilities that attackers can exploit.
  • Example: An employee uses an outdated mobile operating system or outdated apps, making the device susceptible to known vulnerabilities that could be patched by MDM policies.

3. Lost or Stolen Devices

  • Risk: If devices are lost or stolen and not remotely locked or wiped, attackers may easily gain access to the device’s data.
  • Impact: Stolen devices can lead to unauthorized access to corporate data, potentially causing a data breach.
  • Example: A lost phone without MDM can be accessed by a thief who reads emails or downloads sensitive files from cloud storage.

4. Lack of Encryption

  • Risk: Without MDM, devices may not automatically enforce encryption of stored data or communications.
  • Impact: If a device is compromised or physically stolen, sensitive data could be exposed.
  • Example: A mobile device that doesn’t have full disk encryption is lost, and its unencrypted files are accessible to unauthorized individuals.

5. Application and Software Risks

  • Risk: MDM provides the ability to manage and restrict which apps can be installed on devices, reducing the risk of malicious or unauthorized apps.
  • Impact: Employees may install risky or unverified applications that could contain malware or perform unauthorized actions.
  • Example: An employee installs an unapproved third-party app that turns out to be a malware-infested tool, compromising the device and network.

6. Shadow IT (Unapproved Devices and Apps)

  • Risk: Employees may bypass IT policies and use their personal, unmanaged devices and applications to access corporate resources (shadow IT).
  • Impact: This creates blind spots in the organization’s security posture and exposes sensitive data to unauthorized access.
  • Example: An employee uses their personal tablet to access the corporate network without IT’s knowledge, creating a potential security risk.