An organization permits employees to access corporate email and proprietary internal applications on their personal mobile devices under a Bring Your Own Device (BYOD) policy. The IT security administrator must ensure that corporate data can be erased remotely if a device is lost or an employee departs, without destroying the employee's personal photos and files. Which of the following security controls BEST fulfills this requirement?
- ContainerizationAnswer
- BFull device remote wipe policy
- CWPA2-Personal authentication enforcement
- DPhysical security cable locks
Answer
Containerization separates corporate data from personal data on mobile devices, allowing administrators to execute a selective wipe of business information while leaving personal files intact.
Containerization establishes an isolated, encrypted environment on personal devices specifically for corporate data and applications. Through MDM/MAM administration, IT teams can issue a selective wipe command that removes only the corporate container and its encrypted keys, preserving the user's personal media, personal apps, and configuration settings.
Step-by-Step Solution
Key Concept
BYOD Security Controls and Mobile Containerization