ISACA Certified Information Systems Auditor (CISA) ExamDomain 5: Protection of Information AssetsMedium

A CISA is evaluating an organization's security policies. The organization recently implemented a 'Bring Your Own Device' (BYOD) policy. Which of the following is the MOST critical policy component that the CISA should verify is adequately addressed to mitigate associated risks?

  1. AA policy for reimbursement of data plans and device upgrades for BYOD users.
  2. BRequirements for the installation of Mobile Device Management (MDM) software on all BYOD devices.
  3. CDetailed instructions for connecting personal devices to the corporate Wi-Fi network.
  4. DA clear definition of acceptable use for personal devices accessing corporate resources.
Show answer & explanation

Correct answer: B. Requirements for the installation of Mobile Device Management (MDM) software on all BYOD devices.

While acceptable use is important, the MOST critical component for mitigating the inherent risks of BYOD is the requirement for MDM software. MDM allows the organization to enforce security policies (e.g., encryption, password strength), remotely wipe corporate data in case of loss or theft, and isolate corporate applications from personal data, directly addressing potential data leakage and unauthorized access risks.

Why the other options are wrong

  • A. Reimbursement policies are administrative and do not directly mitigate security risks.
  • C. Connection instructions are operational details, not a core risk mitigation policy component.
  • D. Acceptable use is important but less critical for risk mitigation than technical controls like MDM.

BYOD Security Policy

A set of rules and guidelines governing the secure use of personally owned devices for accessing corporate resources, typically including requirements for device management, data protection, and acceptable use.

  • Balances user convenience with corporate security.
  • Requires strong technical and administrative controls.
  • MDM is a cornerstone for enforcing security.

Memory trick: Your personal phone, our corporate data: MDM is the bridge.

More Domain 5: Protection of Information Assets questions