Where and how do you access your work data? Usually organizations store data in a centralized place which only authorized people can access. Determining who has access, how, when, and with which device will be the focus of this module.
Endpoint Protection: Securing "End User" Devices
To access that information, you would typically need a digital device. Any device that is able to access that data, such as a laptop, a tablet, or a mobile phone, is called an endpoint device. Endpoint protection is the practice of securing these end-user devices from cybersecurity threats.
Mobile Device Management: Managing Work Devices
Mobile device management (MDM), also known as Enterprise Mobility Management (EMM), is a security practice which uses software to monitor, manage, and safeguard mobile devices with the aim of protecting an organization’s assets.
Using MDM requires security policies, software, and processes that manage mobile device inventory, protect the device’s data, content, and applications, and govern mobile device use. In an MDM program, employees receive dedicated work devices such as a work laptop. If they use their own personal devices, such as mobile phones for work, those can be enrolled remotely. MDM grants different devices access depending on the employee’s role, allowing them to access certain types of organizational email and data. Many MDM systems also include GPS tracking, secure VPN, and password-protected applications to ensure optimal data security.
What Your Organization Needs to Get Started: Policies, Administrators, and Honesty
In the device security policy module, we mentioned why it is crucial for organizations to have a security policy in place. These policies help staff to properly secure devices and also help the organization to implement access control.
When using MDM software, it is important for the organization to assign a staff member to the role of mobile device manager to enforce these policies. Network or security administrators often take up this role, where they will be tasked with determining what applications can be used on the devices enrolled in the program, what type of data can be stored, and how to enforce screen locks on the devices.
Some of these steps might seem intrusive to staff, especially if they use personal devices for work. Therefore, it is important for the tool’s administrator to be honest about what the device management tool can do. This includes what applications it can read and what rights the administrator has once the device is onboarded onto the MDM software.
Setting Expectations For Your Organization About MDM
MDM can feel intrusive to some people. For this reason, it is best for the organization to explain the technology and how it works to everyone on staff. If the MDM software you are implementing can see apps and read data, staff members should know this.
Additionally, you should decide how soon the organization can take action after an incident occurs. For example, your organization should decide how to handle lost or stolen devices and how soon you will remotely wipe a device after it has been reported lost or stolen. You may want to involve your legal team in these conversations.
You can also choose to have authentication requirements on work devices. This requires staff members to log in every time they want to access data from the organization’s network. This ensures that only authorized personnel can access your organization’s data.
Do You Need an MDM?
MDM policies provide insight into how your staff are using their mobile devices and allow you to govern how these devices are used. By using MDM software, you can detect a breach in your system and can initiate a solution to the threat.
But before implementing MDM policies, organizations like yours need to ask, “What do we want to protect?”
For example:
-
Do we need to enable a passcode on all devices?
-
Should we disable the device’s camera?
-
Can we customize work devices? If so, how much?
-
Do we need to set virtual geographic boundaries for devices?
If these are steps your organization needs to take, then MDM is the right solution for you.
Benefits of Mobile Device Management: More Control Over Work Devices
There are various benefits of using mobile device management in your organization.
For one, MDM makes it possible for IT administrators to determine how users are granting permissions for data, as well as restrict the sharing of information and enforce strong passwords. As a result, they can limit misuse of devices and the risk of data leaks. MDM can also lower the risk of malware and hacking by creating a layer of security protecting the company from phishing, malware, and other types of attacks.
Another benefit of using MDM software is that it facilitates regular updates for all the enrolled work devices in your organization, which ensures compliance with existing device policies.
Additionally, the remote support capabilities of MDM makes it easy for administrators to address any technical problems employees are experiencing while using work devices in remote locations. MDM software also has the ability to track devices and set geo-locks to secure data and track the device’s location.
Choosing MDM Software
When choosing MDM software, you should consider the following features. A good MDM should:
-
Require the setting of a password/passcode and enforce a certain strength level
-
Have remote configuration and monitoring capabilities
-
Allow for remote wipe
-
Have a backup and restore function
-
Enforce device and data encryption
-
Have malware detection capabilities
-
Restrict access to specific apps and data based on location
Additionally, some MDM software packages have options for VPN and Wi-Fi configuration and management. We recommend choosing MDM software with all these features. Make sure whichever software you choose is also cost-effective and easy for the administrator to use.
Pros of MDM
MDM is an effective way of forcing a device to reach your desired level of compliance. For example, device owners cannot turn off the device’s firewall, halt software updates, or download applications that are not approved. Administrators will also find that most MDM software is easy to deploy. It can even be pre-configured into devices and distributed amongst different employees. Due to the commoditization of MDM software, MDM is also becoming inexpensive and buyers can get affordable software at competitive prices.
Cons of MDM
There is, however, a downside to using MDM. MDM does not offer 100% device compliance or protection against brute force or automated attacks. There is no way of managing high-risk compliance issues such as minimizing the amount of time data is stored on a device, SSH key encryption, or securing plain-text two-factor backup codes. MDM also offers limited visibility, which means it provides only a small number of vital data points about a device. MDM can also take away people’s agency and privacy, which can have a negative impact on employees’ productivity and morale.
Should You Use MDM?
MDM is not for every organization. There are a lot of factors to consider before deciding to implement MDM software in your organization. Some countries have data protection laws that require organizations to proactively manage devices. In that case, NGOs based in these countries have a strong motivation to implement MDM solutions. For organizations that are at high risk of digital security threats, MDM allows you to quickly respond to incidents and have better insight into what’s happening within the organization in terms of digital security. However, MDM does come with trade-offs in terms of complexity and privacy. NGOs should weigh the benefits and disadvantages of using MDM and consult digital security experts before implementing this software.