Manage mobile and BYOD security from enrollment through retirement

A secure mobile program distinguishes company-owned and personal devices, documents privacy boundaries, enrolls management before access, protects business data, and prepares for loss, reassignment, and retirement.

Executive summary

What you need to know

A secure mobile program distinguishes company-owned and personal devices, documents privacy boundaries, enrolls management before access, protects business data, and prepares for loss, reassignment, and retirement.

Potentially affected

Smartphones and tablets that access business mail, files, applications, identity services, Wi-Fi, VPN, certificates, physical-access credentials, messaging, or administrative systems.

DSE recommendation

Choose approved ownership models, document management and privacy boundaries, require enrollment and supported software, control business data, create a lost-device runbook, and verify secure reassignment or disposal.

Source fact: mobile security is a lifecycle

NIST SP 800-124 Rev. 2 treats mobile-device security as a lifecycle that includes identifying requirements, performing risk assessment, implementing and testing a solution, operating and maintaining it, and disposing of devices securely. The guidance covers organization-owned and personally owned devices and emphasizes that controls depend on ownership, deployment method, data sensitivity, threats, and available platform capabilities. It is a federal publication that other organizations can adapt rather than a universal mandate for one mobile platform.

The full NIST mobile-device security guidance describes enterprise mobility management, application controls, authentication, encryption, network protections, monitoring, and incident response. Platform features differ. For example, a managed work profile can separate organizational applications and data on some Android deployments, while Apple enrollment types expose different management, privacy, lock, and erase capabilities. Confirm the behavior of the exact operating system, enrollment mode, and management service instead of promising a control that the selected model cannot perform.

Define ownership and privacy before enrollment

Publish which models are allowed: fully managed company device, company-owned device with limited personal use, or bring your own device. For each model, state what administrators can inventory, configure, monitor, lock, remove, or erase; what they cannot see; which business applications and data are allowed; and what happens during loss, investigation, departure, or legal preservation. Obtain acknowledgement before access is granted. A BYOD agreement should not imply full-device control if management can remove only the work profile.

Connect enrollment to an authoritative identity and require supported software, device encryption, screen lock, secure authentication, and approved management state before issuing mail, VPN, Wi-Fi, application, or physical-access credentials. Block devices that are rooted, jailbroken, unsupported, or materially noncompliant according to the organization’s tested policy.

DSE recommendation: operate from a controlled checklist

  1. Record device identity, serial or management ID, ownership, assigned person, operating system, enrollment type, issued credentials, approved exceptions, and next review date.
  2. Separate business data with managed applications, profiles, containers, or access policies appropriate to the platform. Limit unmanaged export, backup, copy, and sharing where the business risk requires it.
  3. Deploy operating-system and application updates in measured waves. Monitor support status, compliance, failed enrollment, disabled protection, and devices that stop checking in.
  4. Prepare a lost-device procedure that authenticates the reporter, revokes sessions and credentials, attempts the supported lock or work-data removal, preserves evidence, assesses notification duties, and records each action.
  5. For reassignment or return, remove business identities and data, revoke certificates and tokens, confirm required preservation, perform the supported wipe, and verify the device at the setup screen before reissue.
  6. For BYOD departure, remove organizational access and managed data without claiming that personal data was erased unless the platform evidence proves it.

Test enrollment, offline behavior, lost-device response, replacement, work-data removal, and full retirement on representative devices. Keep an alternate contact and access path for employees whose phone is unavailable; a recovery process that depends on the missing device is not a complete plan.

Primary reference

Review the official source

NIST SP 800-124 Rev. 2: Mobile Device Security · Published May 17, 2023

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE