SSCP Systems Security Certified PractitionerSecurity Operations and AdministrationMedium

A company is implementing a new BYOD (Bring Your Own Device) policy. To ensure that personal devices accessing corporate resources maintain a minimum security posture without directly managing the device's operating system, which of the following solutions would be MOST appropriate?

  1. ANetwork Access Control (NAC)
  2. BData Loss Prevention (DLP)
  3. CMobile Device Management (MDM)
  4. DMobile Application Management (MAM)
Show answer & explanation

Correct answer: D. Mobile Application Management (MAM)

Mobile Application Management (MAM) allows organizations to manage and secure corporate applications and data on personal devices without taking full control of the entire device, which is ideal for BYOD scenarios where users expect privacy for their personal data.

Why the other options are wrong

  • A. NAC controls network access based on device health but doesn't manage applications or data on the device itself for BYOD.
  • B. DLP prevents data exfiltration but doesn't manage the security posture of the applications or device itself in a BYOD context.
  • C. MDM provides full device control, which is often intrusive and not preferred by users in BYOD scenarios.

Mobile Application Management (MAM)

MAM is a type of software that enables IT administrators to manage and protect corporate applications and data on mobile devices, often used in BYOD environments to separate business and personal data.

  • Manages specific applications, not the entire device.
  • Ideal for BYOD scenarios to respect user privacy.
  • Enforces policies like data encryption, copy/paste restrictions within corporate apps.
  • Complements or can be used instead of MDM.

Memory trick: BYOD is about balancing corporate security with personal device freedom.

More Security Operations and Administration questions