Mobile Hardening Techniques
Summary
PDF p.267Hardening mobile devices involves applying similar security measures as traditional desktops, such as OS patches, strong passwords, and endpoint protection. However, mobile devices require additional measures due to their unique features and higher risk of physical loss or theft.
In plain words
Supplementary — not from your PDFMobile devices need desktop-style protection (patches, strong authentication, endpoint protection, least privilege) plus extra measures for loss and theft (remote wipe, encryption, lock screens), app permissions, and radios (GPS, Bluetooth, NFC). Deployment models: BYOD (employee-owned; flexible but riskier), COBO (corporate, business only), COPE (corporate, personal use allowed) and CYOD (choose from an approved list). MDM (Intune, Apple MDM, Android Enterprise) enforces policy, inventories devices, distributes apps and wipes lost devices.
Detailed explanation
PDF p.267-
Similarities with Desktops
- OS Patches: Regular updates to fix vulnerabilities.
- Strong Passwords: Use unique, complex passwords.
- Endpoint Protection: Install antivirus and antimalware software.
- Least Privilege: Limit user permissions to necessary functions.
-
Unique Mobile Features
- Physical Loss/Theft: Implement remote wiping, encryption, and secure lock screens.
- App Permissions: Manage app access to data and resources.
- GPS, Bluetooth, NFC: Secure these features to prevent attacks.
Deployment Models
Deployment Models
-
Bring Your Own Device (BYOD)
- Ownership: Employee-owned.
- Compliance: Must meet organizational requirements.
- Risks: Mixing personal and professional data.
-
Corporate Owned, Business Only (COBO)
- Ownership: Organization-owned.
- Usage: Business purposes only.
-
Corporate Owned, Personally Enabled (COPE)
- Ownership: Organization-owned.
- Usage: Allows personal use within acceptable use policies.
-
Choose Your Own Device (CYOD)
- Ownership: Organization-owned.
- Choice: Employees select from a preapproved list.
Considerations
- BYOD: Cost savings and flexibility but higher security risks.
- COPE: Greater control and security but higher equipment costs.
- CYOD: Balance between control and employee choice.
Mobile Device Management (MDM)
MDM Functions
- Inventory Management: Track all devices accessing corporate resources.
- Security Policies: Enforce encryption, screen locks, and other security measures.
- Remote Capabilities: Lock or wipe devices if lost or stolen.
- Configuration Management: Centralize and enforce device settings.
- Updates and Patches: Ensure devices are protected against vulnerabilities.
- Quarantine Noncompliant Devices: Remove or isolate devices that don't meet security standards.
Common MDM Tasks
- App Distribution and Updates: Manage enterprise applications.
- Email Management: Configure and secure corporate email accounts.
- Geo-Tracking and Geofencing: Monitor device locations.
- App Allow/Block Listing: Control which apps can be installed.
- Internet Access Control: Manage web access and usage.
Popular MDM Platforms
- Apple MDM: Built into macOS, iOS.
- Android Enterprise: Google's solution for Android devices.
- Platform-Agnostic Solutions: Microsoft Intune, VMware AirWatch, IBM MaaS360.
Important terms
taken from the text above- OS Patches
- Regular updates to fix vulnerabilities.
- Strong Passwords
- Use unique, complex passwords.
- Endpoint Protection
- Install antivirus and antimalware software.
- Least Privilege
- Limit user permissions to necessary functions.
- Physical Loss/Theft
- Implement remote wiping, encryption, and secure lock screens.
- App Permissions
- Manage app access to data and resources.
- GPS, Bluetooth, NFC
- Secure these features to prevent attacks.
- Ownership
- Employee-owned.
- Choice
- Employees select from a preapproved list.
- BYOD
- Cost savings and flexibility but higher security risks.
- COPE
- Greater control and security but higher equipment costs.
- CYOD
- Balance between control and employee choice.
- Inventory Management
- Track all devices accessing corporate resources.
- Security Policies
- Enforce encryption, screen locks, and other security measures.
- Remote Capabilities
- Lock or wipe devices if lost or stolen.
- Configuration Management
- Centralize and enforce device settings.
- Updates and Patches
- Ensure devices are protected against vulnerabilities.
- Quarantine Noncompliant Devices
- Remove or isolate devices that don't meet security standards.
- App Distribution and Updates
- Manage enterprise applications.
- Email Management
- Configure and secure corporate email accounts.
- Geo-Tracking and Geofencing
- Monitor device locations.
- App Allow/Block Listing
- Control which apps can be installed.
- Internet Access Control
- Manage web access and usage.
- Apple MDM
- Built into macOS, iOS.
- Android Enterprise
- Google's solution for Android devices.
- Platform-Agnostic Solutions
- Microsoft Intune, VMware AirWatch, IBM MaaS360.
Examples & real-world scenarios
Supplementary — not from your PDF- MDM enforcing a 6-digit PIN and encryption.
- Remote wiping a lost phone.
- A CYOD programme offering three approved models.
Scenario
A company wants tight control of mobile data but also wants staff to be able to use their phones personally. COPE gives the company ownership and control while allowing personal use under policy.
Common mistakes
Supplementary — not from your PDF- Mixing up COPE (personal use allowed) and COBO (business only).
- Allowing BYOD without any MDM or container separation.
Practical skills
Supplementary — not from your PDF- Choose a deployment model and MDM policy for an organization.
What I should remember
Key Points PDF p.267- Mobile Hardening: Apply OS patches, strong passwords, endpoint protection, and least privilege.
- Unique Features: Implement remote wiping, encryption, secure lock screens, and manage app permissions.
- Deployment Models: Choose between BYOD, COBO, COPE, and CYOD based on organizational needs.
- MDM: Use MDM to manage, secure, and enforce policies on mobile devices.