NIST Protect - Mobile Device Management
Mobile Device Management (MDM):
- MDM enables secure management of laptops, tablets, and mobile phones by ensuring data protection and maintaining compliance with security policies. Here are a few key threats:
1. Unauthorized Access
- Risk: Devices not managed by MDM may not have proper access controls (e.g., strong passwords, biometrics, multi-factor authentication).
- Impact: Employees may access sensitive company resources from untrusted or compromised devices.
- Example: An employee’s personal phone, without enforced MFA or strong passwords, accesses corporate email or VPN, potentially leading to unauthorized access to internal systems.
2. Inconsistent Security Policies
- Risk: Without MDM, it’s difficult to enforce consistent security policies across all devices, leading to non-compliance with organizational or regulatory requirements.
- Impact: Security gaps may exist on certain devices, creating vulnerabilities that attackers can exploit.
- Example: An employee uses an outdated mobile operating system or outdated apps, making the device susceptible to known vulnerabilities that could be patched by MDM policies.
3. Lost or Stolen Devices
- Risk: If devices are lost or stolen and not remotely locked or wiped, attackers may easily gain access to the device’s data.
- Impact: Stolen devices can lead to unauthorized access to corporate data, potentially causing a data breach.
- Example: A lost phone without MDM can be accessed by a thief who reads emails or downloads sensitive files from cloud storage.
4. Lack of Encryption
- Risk: Without MDM, devices may not automatically enforce encryption of stored data or communications.
- Impact: If a device is compromised or physically stolen, sensitive data could be exposed.
- Example: A mobile device that doesn’t have full disk encryption is lost, and its unencrypted files are accessible to unauthorized individuals.
5. Application and Software Risks
- Risk: MDM provides the ability to manage and restrict which apps can be installed on devices, reducing the risk of malicious or unauthorized apps.
- Impact: Employees may install risky or unverified applications that could contain malware or perform unauthorized actions.
- Example: An employee installs an unapproved third-party app that turns out to be a malware-infested tool, compromising the device and network.
6. Shadow IT (Unapproved Devices and Apps)
- Risk: Employees may bypass IT policies and use their personal, unmanaged devices and applications to access corporate resources (shadow IT).
- Impact: This creates blind spots in the organization’s security posture and exposes sensitive data to unauthorized access.
- Example: An employee uses their personal tablet to access the corporate network without IT’s knowledge, creating a potential security risk.