While testing the policy, the engineer temporarily picks up one of the unattended phones and is able to immediately access corporate email, financial reports, and messaging applications without encountering any authentication barrier at the device level.
The organization determines that the exposure stems from inadequate baseline security requirements for personally owned devices used to access corporate resources.
Which BYOD security guideline would most directly mitigate this exposure?
The immediate weakness is absence of device-level authentication. A strong device passcode directly prevents an unauthorized person who physically obtains an unattended smartphone from immediately opening corporate applications and data. Encryption protects stored information, but normally depends on authentication controls to prevent unauthorized interactive access. Separating business and personal information improves BYOD governance but does not stop someone from using an already accessible phone. Application-specific passwords provide additional defense, yet the scenario explicitly identifies the missing baseline control at the device level. CEH v13 Module 17 includes mobile device management and mobile-security guidelines, while established BYOD guidance likewise recommends strong passwords, automatic locking, and authentication controls on personally owned devices accessing organizational data. Therefore, option B most directly addresses the stated exposure.
================
Currently there are no comments in this discussion, be the first to comment!