An enterprise allows employees to access internal business applications on personal smartphones under a Bring Your Own Device (BYOD) policy. Management mandates that corporate data must be protected against unauthorized data leakage to personal applications, but the company must not have administrative control over personal files or the capability to wipe personal data from the device. Which management strategy should the IT administrator deploy to satisfy this security requirement?
- Mobile Application Management (MAM) utilizing containerization and data loss prevention (DLP) policiesAnswer
- BFull Mobile Device Management (MDM) profile enrollment enforcing mandatory full-device remote wipes
- CHardware-level access control restricting device registration based on International Mobile Subscriber Identity (IMSI) numbers
- DClient account reconfiguration to use POP3 on port 993 for corporate data containment
Answer
Implement Mobile Application Management (MAM) utilizing containerization and data loss prevention (DLP) policies.
Mobile Application Management (MAM) creates an isolated container for corporate applications and data while applying Data Loss Prevention (DLP) rules to prevent copying content to personal apps. Because MAM only manages corporate apps and data, the administrator cannot view or wipe personal files on a BYOD smartphone, fully satisfying all policy requirements.
Step-by-Step Solution
Key Concept
Mobile Application Management (MAM) vs Mobile Device Management (MDM)