Device security guidance
Guidance for organisations on how to choose, configure and use devices securely.
Pages
Page 37 of 37
Action 5 - Put technical controls in place
Introduction
Once you have settled on your deployment approach, you will need to choose the technical controls that will enforce your BYOD policy.
The controls available to you will depend upon your chosen deployment approach and the products you use to implement it. You should refer to vendor guidance to help you decide on the right controls for your chosen policies.
Suitable technical controls
Below are some examples of suitable technical controls for each deployment type, along with some notes on implementation and links to related resources.
It is important that once you have your technical controls in place, you should penetration test your solutions to ensure they are fit for purpose. This must be completed before full deployment across your chosen user groups.
You should also ensure that you conduct employee risk training, covering topics such as:
- How to minimise risks by not using jailbroken or rooted devices
- Ensuring devices, applications and browsers are kept up to date
Web browsers
- Enforce strong authentication controls on your corporate services, like MFA.
- Ensure any Cloud Access Security Brokers (CASB) used to control session-level privileges in corporate services have permissions set appropriately.
Virtual Desktop Infrastructure (VDI)/Remote Desktop/Remote Apps
- Focus primarily on securing your corporate resources, including the remote landing machine and secondarily on the personal device.
• Only expose corporate resources that the individual user or group requires, when they require it through Role Based Access Control (RBAC). Remove access at all other times.
• NCSC blogs on protecting your management interfaces and mitigating malware and ransomware attacks may help.
- Restrict access from legacy operating systems, browsers, and authentication protocols
- Enforce strong authentication (minimum MFA) for access to corporate resources
- Use sign-in risk assessment tools
• Some authentication providers assess the risk of sign-in events using information such as geographic location and device compliance checks. Depending on the assessed level of risk, you can then block access, allow access, or gain further assurance of the request
- Prevent multiple user sessions, if possible
• Only allowing a user to access your resources in a single session will help to flag potentially suspicious activity if a second session is attempted
- Block direct RDP (Remote Desktop Protocol) access within the VDI
- Use controls that minimise the effect of theft of the device and/or credentials
• Strong authentication (Multifactor authentication should be used as a minimum)
• Do not allow the transfer of data from your VDI to the user’s device or applications by, for example, disabling clipboard and drive redirections
• Limit the corporate resources available to users to only that which they require to do their work. This will help to minimise the impact of any compromise.
- Gain as much device assurance as possible
• If your solution allows it, configure checks for malicious software on the user device and virtual machines.
- Set idle times and take action when these times are up
• For example, disconnect and lock sessions after set time limits
• Idle times could also trigger controls such as locking machine screens, requiring re-authentication to unlock
- Do not allow users to install unapproved software directly in your virtual environment.
- Use controls to limit the sharing or removal of corporate data outside of the VDI, such as:
• Do not allow printing from the VDI
• Prevent screen capture and screen recording, if possible
- Encrypt corporate data in transit and at rest
- Use logging to track all activities related to the VDI environment.
• You should aim for an equivalent level of logging as on a corporately owned workstation
Bootable OS
- Ensure corporate files are stored in the correct repositories
- Use full volume encryption to protect from compromise or theft
- In some circumstances Secure Boot may be an option, but this will depend on the BYOD hardware in use, and the willingness and ability of your IT department to manage its complexities.
- Keeping bootable OS images up to date
• eg Windows-to-Go does not support in-place upgrades, so this will have to be supported
- Follow all vendor best practices to minimise chances of accidental data leakage
Mobile Device Management (MDM)
The following controls are focused only on BYOD solutions. Because MDMs also support corporately owned and fully managed models, there are likely to be other controls available which are not be suitable for BYOD.
- Device compliance monitoring
• Including Application and device update status, jailbreak detection, presence of banned apps
• Use reporting if available from device attestation to provide assertions of device compliance and device health
- Install applications from allowed lists only, using Enterprise application catalogues
- Prompt users to update their devices and corporate applications where possible and block access if not compliant (may not be applicable to BYOD)
- Monitor and report on the status of installed corporate apps (may not be applicable to BYOD)
- Ensure you can remotely remove access to corporate resources
- Restrict the ability to copy data between work and personal environments
- Only expose corporate resources that the individual user/group requires
- Set ‘terms of use’ within your MDM if it has this facility, use SyOps, and communicate privacy boundaries through the MDM.
• For example, require digital training package(s) to be completed before users are added to a BYOD-allow list
Mobile Application Management (MAM)
The following controls are focused only on BYOD solutions (MAM-WE). There are likely be other controls available which may not be suitable for BYOD.
- Only provide access to corporate services/applications from Enterprise managed/approved application stores.
- Enforce App version compliance and push updates where possible
- Ensure you can remotely remove access to corporate applications and associated data
- Restrict the ability to copy data from corporate apps to non-corporate apps.
- Use strong authentication for access to corporate applications
- Audit and log access to corporate applications and resources
- Only expose corporate resources that the individual user/group requires
Hybrid approaches
Controls for hybrid approaches will be a blend of the most appropriate features available from MDM and MAM-WE to balance application and device controls with user privacy. See the above technical controls available for each solution and consult vendor documentation to ensure that the two controls will complement each other. These are often packaged within MDM, UEM or EMM solutions.