Ravindra BagaleCourses & study guides

44. Mobile Device Security – Android, iPhone, Bluetooth and Wi-Fi

44.6 MDM and BYOD – SME Concepts for Sahyadri Traders

MDM (Mobile Device Management) = company policy on the phone: inventory, passcode enforce, remote wipe, app allow-list, encrypt at rest.

BYOD (Bring Your Own Device) = staff personal phone used for work email / WhatsApp Business. Risk: company data on a phone IT does not fully control.

SME pattern for fictional Sahyadri Traders (Pune HQ):

Choice Idea
Corporate-owned MDM enrolled; wipe OK on exit; separate from kids' games
BYOD light Container / work profile; no full wipe of personal photos without policy clarity
Blocked Unmanaged phones with full ERP admin + sideload freedom

Blue minimum: screen lock enforced, OS version floor, remote wipe for lost corporate phones, separate work apps, disable unknown sources via policy where platform allows.

Red team (attacker) does Blue team (defender) detects / stops
Steals unmanaged BYOD with ERP token MDM / work profile; short session TTL; wipe / revoke
Leaves ex-employee phone enrolled Offboarding checklist: wipe + account revoke same day
Phishes MDM enrollment into fake portal Official IT enrollment QR only; certificate pinning stories

Ravindra Bagale's Tip

Students say "MDM = spying on staff WhatsApp". Good MDM = protecting company data + wiping lost phones – the policy must be clear and lawful. Interview: the corporate-owned vs BYOD trade-off in two sentences. Now let's move on.

Lab

Write a 10-line BYOD policy draft for Sahyadri (Nashik sales tablets): passcode, patch age, approved apps, lost-phone call tree (Rani → Amir IT). No real staff surveillance tools.