{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/mobile-byod-security-enrollment-retirement-lifecycle/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/mobile-byod-security-enrollment-retirement-lifecycle/",
        "slug": "mobile-byod-security-enrollment-retirement-lifecycle",
        "url": "https://update.dsesecurity.com/updates/mobile-byod-security-enrollment-retirement-lifecycle/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/mobile-byod-security-enrollment-retirement-lifecycle.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/mobile-byod-security-enrollment-retirement-lifecycle/"
        },
        "title": "Manage mobile and BYOD security from enrollment through retirement",
        "summary": "A secure mobile program distinguishes company-owned and personal devices, documents privacy boundaries, enrolls management before access, protects business data, and prepares for loss, reassignment, and retirement.",
        "format": {
            "slug": "checklist",
            "name": "Checklist"
        },
        "priority": {
            "slug": "important",
            "name": "Important"
        },
        "featured": false,
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-07-28T14:22:00+00:00",
        "modified_at": "2026-07-28T14:22:00+00:00",
        "reviewed_on": "2026-07-28",
        "reading_minutes": 3,
        "word_count": 485,
        "potentially_affected": "Smartphones and tablets that access business mail, files, applications, identity services, Wi-Fi, VPN, certificates, physical-access credentials, messaging, or administrative systems.",
        "dse_recommendation": "Choose approved ownership models, document management and privacy boundaries, require enrollment and supported software, control business data, create a lost-device runbook, and verify secure reassignment or disposal.",
        "primary_source": {
            "name": "NIST SP 800-124 Rev. 2: Mobile Device Security",
            "url": "https://csrc.nist.gov/pubs/sp/800/124/r2/final",
            "published_on": "2023-05-17",
            "authority": "National Institute of Standards and Technology"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source fact: mobile security is a lifecycle</h2>\n<p>NIST SP 800-124 Rev. 2 treats mobile-device security as a lifecycle that includes identifying requirements, performing risk assessment, implementing and testing a solution, operating and maintaining it, and disposing of devices securely. The guidance covers organization-owned and personally owned devices and emphasizes that controls depend on ownership, deployment method, data sensitivity, threats, and available platform capabilities. It is a federal publication that other organizations can adapt rather than a universal mandate for one mobile platform.</p>\n<p>The full <a href=\"https://csrc.nist.gov/pubs/sp/800/124/r2/final\" target=\"_blank\" rel=\"noopener noreferrer\">NIST mobile-device security guidance</a> describes enterprise mobility management, application controls, authentication, encryption, network protections, monitoring, and incident response. Platform features differ. For example, a managed work profile can separate organizational applications and data on some Android deployments, while Apple enrollment types expose different management, privacy, lock, and erase capabilities. Confirm the behavior of the exact operating system, enrollment mode, and management service instead of promising a control that the selected model cannot perform.</p>\n\n<h2>Define ownership and privacy before enrollment</h2>\n<p>Publish which models are allowed: fully managed company device, company-owned device with limited personal use, or bring your own device. For each model, state what administrators can inventory, configure, monitor, lock, remove, or erase; what they cannot see; which business applications and data are allowed; and what happens during loss, investigation, departure, or legal preservation. Obtain acknowledgement before access is granted. A BYOD agreement should not imply full-device control if management can remove only the work profile.</p>\n<p>Connect enrollment to an authoritative identity and require supported software, device encryption, screen lock, secure authentication, and approved management state before issuing mail, VPN, Wi-Fi, application, or physical-access credentials. Block devices that are rooted, jailbroken, unsupported, or materially noncompliant according to the organization&#8217;s tested policy.</p>\n\n<h2>DSE recommendation: operate from a controlled checklist</h2>\n<ol>\n<li>Record device identity, serial or management ID, ownership, assigned person, operating system, enrollment type, issued credentials, approved exceptions, and next review date.</li>\n<li>Separate business data with managed applications, profiles, containers, or access policies appropriate to the platform. Limit unmanaged export, backup, copy, and sharing where the business risk requires it.</li>\n<li>Deploy operating-system and application updates in measured waves. Monitor support status, compliance, failed enrollment, disabled protection, and devices that stop checking in.</li>\n<li>Prepare a lost-device procedure that authenticates the reporter, revokes sessions and credentials, attempts the supported lock or work-data removal, preserves evidence, assesses notification duties, and records each action.</li>\n<li>For reassignment or return, remove business identities and data, revoke certificates and tokens, confirm required preservation, perform the supported wipe, and verify the device at the setup screen before reissue.</li>\n<li>For BYOD departure, remove organizational access and managed data without claiming that personal data was erased unless the platform evidence proves it.</li>\n</ol>\n<p>Test enrollment, offline behavior, lost-device response, replacement, work-data removal, and full retirement on representative devices. Keep an alternate contact and access path for employees whose phone is unavailable; a recovery process that depends on the missing device is not a complete plan.</p>",
        "content_text": "Source fact: mobile security is a lifecycle\nNIST SP 800-124 Rev. 2 treats mobile-device security as a lifecycle that includes identifying requirements, performing risk assessment, implementing and testing a solution, operating and maintaining it, and disposing of devices securely. The guidance covers organization-owned and personally owned devices and emphasizes that controls depend on ownership, deployment method, data sensitivity, threats, and available platform capabilities. It is a federal publication that other organizations can adapt rather than a universal mandate for one mobile platform.\nThe full NIST mobile-device security guidance describes enterprise mobility management, application controls, authentication, encryption, network protections, monitoring, and incident response. Platform features differ. For example, a managed work profile can separate organizational applications and data on some Android deployments, while Apple enrollment types expose different management, privacy, lock, and erase capabilities. Confirm the behavior of the exact operating system, enrollment mode, and management service instead of promising a control that the selected model cannot perform.\n\nDefine ownership and privacy before enrollment\nPublish which models are allowed: fully managed company device, company-owned device with limited personal use, or bring your own device. For each model, state what administrators can inventory, configure, monitor, lock, remove, or erase; what they cannot see; which business applications and data are allowed; and what happens during loss, investigation, departure, or legal preservation. Obtain acknowledgement before access is granted. A BYOD agreement should not imply full-device control if management can remove only the work profile.\nConnect enrollment to an authoritative identity and require supported software, device encryption, screen lock, secure authentication, and approved management state before issuing mail, VPN, Wi-Fi, application, or physical-access credentials. Block devices that are rooted, jailbroken, unsupported, or materially noncompliant according to the organization’s tested policy.\n\nDSE recommendation: operate from a controlled checklist\n\nRecord device identity, serial or management ID, ownership, assigned person, operating system, enrollment type, issued credentials, approved exceptions, and next review date.\nSeparate business data with managed applications, profiles, containers, or access policies appropriate to the platform. Limit unmanaged export, backup, copy, and sharing where the business risk requires it.\nDeploy operating-system and application updates in measured waves. Monitor support status, compliance, failed enrollment, disabled protection, and devices that stop checking in.\nPrepare a lost-device procedure that authenticates the reporter, revokes sessions and credentials, attempts the supported lock or work-data removal, preserves evidence, assesses notification duties, and records each action.\nFor reassignment or return, remove business identities and data, revoke certificates and tokens, confirm required preservation, perform the supported wipe, and verify the device at the setup screen before reissue.\nFor BYOD departure, remove organizational access and managed data without claiming that personal data was erased unless the platform evidence proves it.\n\nTest enrollment, offline behavior, lost-device response, replacement, work-data removal, and full retirement on representative devices. Keep an alternate contact and access path for employees whose phone is unavailable; a recovery process that depends on the missing device is not a complete plan.",
        "content_markdown": "## Source fact: mobile security is a lifecycle\n\nNIST SP 800-124 Rev. 2 treats mobile-device security as a lifecycle that includes identifying requirements, performing risk assessment, implementing and testing a solution, operating and maintaining it, and disposing of devices securely. The guidance covers organization-owned and personally owned devices and emphasizes that controls depend on ownership, deployment method, data sensitivity, threats, and available platform capabilities. It is a federal publication that other organizations can adapt rather than a universal mandate for one mobile platform.\n\nThe full [NIST mobile-device security guidance](https://csrc.nist.gov/pubs/sp/800/124/r2/final) describes enterprise mobility management, application controls, authentication, encryption, network protections, monitoring, and incident response. Platform features differ. For example, a managed work profile can separate organizational applications and data on some Android deployments, while Apple enrollment types expose different management, privacy, lock, and erase capabilities. Confirm the behavior of the exact operating system, enrollment mode, and management service instead of promising a control that the selected model cannot perform.\n\n## Define ownership and privacy before enrollment\n\nPublish which models are allowed: fully managed company device, company-owned device with limited personal use, or bring your own device. For each model, state what administrators can inventory, configure, monitor, lock, remove, or erase; what they cannot see; which business applications and data are allowed; and what happens during loss, investigation, departure, or legal preservation. Obtain acknowledgement before access is granted. A BYOD agreement should not imply full-device control if management can remove only the work profile.\n\nConnect enrollment to an authoritative identity and require supported software, device encryption, screen lock, secure authentication, and approved management state before issuing mail, VPN, Wi-Fi, application, or physical-access credentials. Block devices that are rooted, jailbroken, unsupported, or materially noncompliant according to the organization’s tested policy.\n\n## DSE recommendation: operate from a controlled checklist\n\n- Record device identity, serial or management ID, ownership, assigned person, operating system, enrollment type, issued credentials, approved exceptions, and next review date.\n\n- Separate business data with managed applications, profiles, containers, or access policies appropriate to the platform. Limit unmanaged export, backup, copy, and sharing where the business risk requires it.\n\n- Deploy operating-system and application updates in measured waves. Monitor support status, compliance, failed enrollment, disabled protection, and devices that stop checking in.\n\n- Prepare a lost-device procedure that authenticates the reporter, revokes sessions and credentials, attempts the supported lock or work-data removal, preserves evidence, assesses notification duties, and records each action.\n\n- For reassignment or return, remove business identities and data, revoke certificates and tokens, confirm required preservation, perform the supported wipe, and verify the device at the setup screen before reissue.\n\n- For BYOD departure, remove organizational access and managed data without claiming that personal data was erased unless the platform evidence proves it.\n\nTest enrollment, offline behavior, lost-device response, replacement, work-data removal, and full retirement on representative devices. Keep an alternate contact and access path for employees whose phone is unavailable; a recovery process that depends on the missing device is not a complete plan."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo.png"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/mobile-byod-security-enrollment-retirement-lifecycle/",
                "url": "https://update.dsesecurity.com/updates/mobile-byod-security-enrollment-retirement-lifecycle/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-07-28"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/mobile-byod-security-enrollment-retirement-lifecycle/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Manage mobile and BYOD security from enrollment through retirement",
                        "item": "https://update.dsesecurity.com/updates/mobile-byod-security-enrollment-retirement-lifecycle/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/mobile-byod-security-enrollment-retirement-lifecycle/#article",
                "identifier": "https://update.dsesecurity.com/updates/mobile-byod-security-enrollment-retirement-lifecycle/",
                "url": "https://update.dsesecurity.com/updates/mobile-byod-security-enrollment-retirement-lifecycle/",
                "headline": "Manage mobile and BYOD security from enrollment through retirement",
                "description": "A secure mobile program distinguishes company-owned and personal devices, documents privacy boundaries, enrolls management before access, protects…",
                "abstract": "A secure mobile program distinguishes company-owned and personal devices, documents privacy boundaries, enrolls management before access, protects business data, and prepares for loss, reassignment, and retirement.",
                "articleBody": "Source fact: mobile security is a lifecycle\nNIST SP 800-124 Rev. 2 treats mobile-device security as a lifecycle that includes identifying requirements, performing risk assessment, implementing and testing a solution, operating and maintaining it, and disposing of devices securely. The guidance covers organization-owned and personally owned devices and emphasizes that controls depend on ownership, deployment method, data sensitivity, threats, and available platform capabilities. It is a federal publication that other organizations can adapt rather than a universal mandate for one mobile platform.\nThe full NIST mobile-device security guidance describes enterprise mobility management, application controls, authentication, encryption, network protections, monitoring, and incident response. Platform features differ. For example, a managed work profile can separate organizational applications and data on some Android deployments, while Apple enrollment types expose different management, privacy, lock, and erase capabilities. Confirm the behavior of the exact operating system, enrollment mode, and management service instead of promising a control that the selected model cannot perform.\n\nDefine ownership and privacy before enrollment\nPublish which models are allowed: fully managed company device, company-owned device with limited personal use, or bring your own device. For each model, state what administrators can inventory, configure, monitor, lock, remove, or erase; what they cannot see; which business applications and data are allowed; and what happens during loss, investigation, departure, or legal preservation. Obtain acknowledgement before access is granted. A BYOD agreement should not imply full-device control if management can remove only the work profile.\nConnect enrollment to an authoritative identity and require supported software, device encryption, screen lock, secure authentication, and approved management state before issuing mail, VPN, Wi-Fi, application, or physical-access credentials. Block devices that are rooted, jailbroken, unsupported, or materially noncompliant according to the organization’s tested policy.\n\nDSE recommendation: operate from a controlled checklist\n\nRecord device identity, serial or management ID, ownership, assigned person, operating system, enrollment type, issued credentials, approved exceptions, and next review date.\nSeparate business data with managed applications, profiles, containers, or access policies appropriate to the platform. Limit unmanaged export, backup, copy, and sharing where the business risk requires it.\nDeploy operating-system and application updates in measured waves. Monitor support status, compliance, failed enrollment, disabled protection, and devices that stop checking in.\nPrepare a lost-device procedure that authenticates the reporter, revokes sessions and credentials, attempts the supported lock or work-data removal, preserves evidence, assesses notification duties, and records each action.\nFor reassignment or return, remove business identities and data, revoke certificates and tokens, confirm required preservation, perform the supported wipe, and verify the device at the setup screen before reissue.\nFor BYOD departure, remove organizational access and managed data without claiming that personal data was erased unless the platform evidence proves it.\n\nTest enrollment, offline behavior, lost-device response, replacement, work-data removal, and full retirement on representative devices. Keep an alternate contact and access path for employees whose phone is unavailable; a recovery process that depends on the missing device is not a complete plan.",
                "datePublished": "2026-07-28T14:22:00+00:00",
                "dateModified": "2026-07-28T14:22:00+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/mobile-byod-security-enrollment-retirement-lifecycle/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@id": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": "https://update.dsesecurity.com/assets/dse-updates-share.png",
                "articleSection": [
                    "Business Continuity",
                    "Cybersecurity",
                    "IT"
                ],
                "keywords": [
                    "Business Continuity",
                    "Cybersecurity",
                    "IT",
                    "Checklist",
                    "Important priority"
                ],
                "genre": "Checklist",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 485,
                "timeRequired": "PT3M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "NIST SP 800-124 Rev. 2: Mobile Device Security",
                    "url": "https://csrc.nist.gov/pubs/sp/800/124/r2/final",
                    "datePublished": "2023-05-17"
                }
            }
        ]
    }
}