1
00:00:06,480 --> 00:00:08,460
- In this lesson 14.5,

2
00:00:08,460 --> 00:00:11,460
we're gonna continue our
discussion about mobile devices.

3
00:00:11,460 --> 00:00:13,320
But instead of talking about connectivity,

4
00:00:13,320 --> 00:00:16,260
we're gonna talk about
mobile device management.

5
00:00:16,260 --> 00:00:18,930
So mobile device management
encompasses deploying,

6
00:00:18,930 --> 00:00:21,810
securing, monitoring, integrating,

7
00:00:21,810 --> 00:00:24,873
and managing mobile
devices in the workplace.

8
00:00:25,710 --> 00:00:28,170
Now there are three different approaches

9
00:00:28,170 --> 00:00:29,550
that kind of work together,

10
00:00:29,550 --> 00:00:32,640
there's Mobile Device Management,
MDM, which is software

11
00:00:32,640 --> 00:00:35,357
that's used to control
deployment, manage settings,

12
00:00:35,357 --> 00:00:37,890
those settings are gonna
be referred to as policies,

13
00:00:37,890 --> 00:00:40,380
and report on activity and usage.

14
00:00:40,380 --> 00:00:43,770
Then we have Unified
Endpoint Management, or UEM,

15
00:00:43,770 --> 00:00:47,700
which extends the functionality
of MDM to IoT devices

16
00:00:47,700 --> 00:00:49,230
and even to our wearables.

17
00:00:49,230 --> 00:00:50,460
And then we have MAM,

18
00:00:50,460 --> 00:00:52,740
which is Mobile Application Management,

19
00:00:52,740 --> 00:00:56,910
which focuses on the management
of mobile applications.

20
00:00:56,910 --> 00:00:59,880
But before we talk about how
we're managing the devices,

21
00:00:59,880 --> 00:01:02,130
let's talk about who owns the devices

22
00:01:02,130 --> 00:01:03,723
and how they get deployed.

23
00:01:05,220 --> 00:01:08,610
There are three primary
types of device ownership,

24
00:01:08,610 --> 00:01:11,790
which correspond to how
they're going to be deployed.

25
00:01:11,790 --> 00:01:16,080
BYOD, COPE, and COBO, or C-O-B-O.

26
00:01:16,080 --> 00:01:18,180
Now, BYOD is probably the one

27
00:01:18,180 --> 00:01:19,770
that you're most familiar with.

28
00:01:19,770 --> 00:01:22,350
BYOD stands for Bring Your Own Device,

29
00:01:22,350 --> 00:01:25,980
and that's where users use
their personally owned devices

30
00:01:25,980 --> 00:01:27,750
in the workplace, so they're using

31
00:01:27,750 --> 00:01:29,100
their personally owned devices

32
00:01:29,100 --> 00:01:32,370
for both professional and personal use.

33
00:01:32,370 --> 00:01:36,960
Probably still one of
the most popular types

34
00:01:36,960 --> 00:01:39,360
of device ownership out there.

35
00:01:39,360 --> 00:01:41,550
It's interesting, because
there's questions about,

36
00:01:41,550 --> 00:01:42,900
okay, well who pays for the device?

37
00:01:42,900 --> 00:01:45,660
Does the company give you
a stipend for part of it?

38
00:01:45,660 --> 00:01:47,970
And, you have to allow the company

39
00:01:47,970 --> 00:01:49,770
to have access to your device,

40
00:01:49,770 --> 00:01:51,930
because they're going to
put some security controls

41
00:01:51,930 --> 00:01:53,700
on your device.

42
00:01:53,700 --> 00:01:54,930
The second is COPE,

43
00:01:54,930 --> 00:01:58,290
that stands for Company-issued
Personal Enabled,

44
00:01:58,290 --> 00:02:01,680
where the users get issued
a company-owned device,

45
00:02:01,680 --> 00:02:02,513
but again, they can use it

46
00:02:02,513 --> 00:02:04,740
for both professional and personal use.

47
00:02:04,740 --> 00:02:06,330
But in BYOD, right?

48
00:02:06,330 --> 00:02:09,090
The device was owned by the user,

49
00:02:09,090 --> 00:02:12,813
in COPE, the device is
owned by the company.

50
00:02:13,740 --> 00:02:17,400
And the third option is COBO, or C-O-B-O,

51
00:02:17,400 --> 00:02:19,680
which is Company-issued Business Only,

52
00:02:19,680 --> 00:02:22,680
and that's when users get
issued a company owned device

53
00:02:22,680 --> 00:02:25,860
but it's for professional use
only, end of story, right?

54
00:02:25,860 --> 00:02:28,503
Not to be used at all for personal use.

55
00:02:29,700 --> 00:02:31,470
Now, in all three of these though,

56
00:02:31,470 --> 00:02:36,470
we can use our MDM software
to manage those devices.

57
00:02:36,480 --> 00:02:38,730
Now our Mobile Device Management software

58
00:02:38,730 --> 00:02:42,510
is used to control deployment,
manage settings, policies,

59
00:02:42,510 --> 00:02:45,000
and report on activity and usage.

60
00:02:45,000 --> 00:02:48,420
So our MDM control categories
include device tracking,

61
00:02:48,420 --> 00:02:51,180
device protection, access control,

62
00:02:51,180 --> 00:02:53,550
application and content management.

63
00:02:53,550 --> 00:02:56,400
The MDM solutions can be
local, meaning on-prem,

64
00:02:56,400 --> 00:02:58,293
or they can be cloud-based.

65
00:02:59,910 --> 00:03:01,380
So let's go through each
of those categories,

66
00:03:01,380 --> 00:03:03,180
starting with device tracking.

67
00:03:03,180 --> 00:03:05,880
Two very common things in device tracking

68
00:03:05,880 --> 00:03:09,420
will be geolocation and geofencing.

69
00:03:09,420 --> 00:03:11,070
Geolocation is the process

70
00:03:11,070 --> 00:03:13,440
of determining the object's position

71
00:03:13,440 --> 00:03:18,440
based on GPS, cell triangulation,
or Wi-Fi proximity.

72
00:03:18,540 --> 00:03:19,800
What's it used for?

73
00:03:19,800 --> 00:03:21,900
Well, active device tracking,

74
00:03:21,900 --> 00:03:24,420
user tracking, so, where's our user?

75
00:03:24,420 --> 00:03:26,643
Or even to locate a lost device.

76
00:03:27,540 --> 00:03:31,410
Geofencing is the process of
defining a virtual boundary,

77
00:03:31,410 --> 00:03:35,700
known as a geofence,
around a specific area.

78
00:03:35,700 --> 00:03:37,080
What is it used for in this case?

79
00:03:37,080 --> 00:03:39,750
Well, it can define
where devices can be used

80
00:03:39,750 --> 00:03:41,613
or where they can't be used.

81
00:03:43,890 --> 00:03:45,000
Now for data protection,

82
00:03:45,000 --> 00:03:47,280
some options we have are containerization,

83
00:03:47,280 --> 00:03:51,120
storage segmentation, full
device encryption, FDE,

84
00:03:51,120 --> 00:03:54,063
and DLP, data loss prevention.

85
00:03:55,380 --> 00:03:57,630
Now containerization is the use

86
00:03:57,630 --> 00:04:00,750
of a secure virtual
container, one or more,

87
00:04:00,750 --> 00:04:04,140
and we use those to segregate
high risk applications,

88
00:04:04,140 --> 00:04:07,560
like email or our browser,
we can also use it

89
00:04:07,560 --> 00:04:10,383
to segregate and encrypt
confidential data.

90
00:04:12,060 --> 00:04:14,220
Storage segmentation is a method

91
00:04:14,220 --> 00:04:16,590
to segment personal and corporate data,

92
00:04:16,590 --> 00:04:19,740
and it's also used to
enforce access policies

93
00:04:19,740 --> 00:04:23,490
and encryption policies
by the storage location,

94
00:04:23,490 --> 00:04:26,493
even, if we get very
granular, by the folder.

95
00:04:27,540 --> 00:04:30,270
FDE, full device encryption,
is just what it sounds like,

96
00:04:30,270 --> 00:04:33,120
it requires the entire
device to be encrypted,

97
00:04:33,120 --> 00:04:34,620
including, and this is important,

98
00:04:34,620 --> 00:04:36,333
including any removable media.

99
00:04:37,290 --> 00:04:40,020
And DLP, data loss protection,

100
00:04:40,020 --> 00:04:44,010
is enforcement of DLP
policies, it controls open-in,

101
00:04:44,010 --> 00:04:46,050
so let's say you were
opening a file, right?

102
00:04:46,050 --> 00:04:48,090
What application could it open in?

103
00:04:48,090 --> 00:04:51,273
And it also enforces copy
and paste restrictions.

104
00:04:53,040 --> 00:04:56,100
Our next category is access
control, authentication,

105
00:04:56,100 --> 00:05:00,720
content aware, local wipe and
auto wipe, and screen lock.

106
00:05:00,720 --> 00:05:04,770
Authentication enforces our
password and biometric policies,

107
00:05:04,770 --> 00:05:09,570
for our devices as well
as for content access.

108
00:05:09,570 --> 00:05:12,120
Content-aware is
authentication requirement

109
00:05:12,120 --> 00:05:15,900
based on activity, so access
to a specific resource

110
00:05:15,900 --> 00:05:17,883
or to a specific application.

111
00:05:18,900 --> 00:05:21,180
Then we have local wipe and auto wipe,

112
00:05:21,180 --> 00:05:22,650
that wipes a mobile device

113
00:05:22,650 --> 00:05:26,430
after a pre-specified
number of failed logins,

114
00:05:26,430 --> 00:05:29,520
or it could even be that
it gets wiped if the device

115
00:05:29,520 --> 00:05:33,663
moves outside of a defined
physical boundary or a geofence.

116
00:05:34,740 --> 00:05:37,470
And then screen lock is a
requirement that the screen lock

117
00:05:37,470 --> 00:05:40,020
after X minutes of inactivity,

118
00:05:40,020 --> 00:05:42,330
it can also have forced deauthentication,

119
00:05:42,330 --> 00:05:44,970
it can say it can force
you to deauthenticate

120
00:05:44,970 --> 00:05:48,123
from an access point or
from a wireless network.

121
00:05:50,490 --> 00:05:53,520
Next is content management, application,

122
00:05:53,520 --> 00:05:58,290
content itself, push
notifications, and remote wipe.

123
00:05:58,290 --> 00:06:00,450
Application content management

124
00:06:00,450 --> 00:06:03,000
controls the application installation,

125
00:06:03,000 --> 00:06:04,590
effectively gives you an app catalog,

126
00:06:04,590 --> 00:06:07,770
this is what you can
install on your device.

127
00:06:07,770 --> 00:06:09,570
It enforces the user permission

128
00:06:09,570 --> 00:06:13,230
that's required to install
and to update apps,

129
00:06:13,230 --> 00:06:17,100
and it also might automate the
transparent download of apps

130
00:06:17,100 --> 00:06:18,843
as well as the updates of apps.

131
00:06:20,040 --> 00:06:23,460
Content management controls
access to business content,

132
00:06:23,460 --> 00:06:25,050
it enforces user permissions

133
00:06:25,050 --> 00:06:27,900
required to access or to annotate content,

134
00:06:27,900 --> 00:06:29,640
and it can also be used

135
00:06:29,640 --> 00:06:32,733
to automatically push files to a device.

136
00:06:33,930 --> 00:06:36,900
Push notifications control,
well, what it sounds like,

137
00:06:36,900 --> 00:06:38,010
push notifications.

138
00:06:38,010 --> 00:06:40,380
Now, push notifications
are popups, alerts,

139
00:06:40,380 --> 00:06:42,270
or customized messages.

140
00:06:42,270 --> 00:06:45,660
And then remote wipe is a
remote clean that device,

141
00:06:45,660 --> 00:06:47,610
it's a command sent to a remote device

142
00:06:47,610 --> 00:06:50,370
to delete all or selected content,

143
00:06:50,370 --> 00:06:52,290
it can also just reset that device

144
00:06:52,290 --> 00:06:54,153
right back to factory settings.

145
00:06:56,084 --> 00:06:59,100
So what are some of our mobile
device security concerns?

146
00:06:59,100 --> 00:07:03,090
Jailbreaking, rooting,
sideloading, camera access,

147
00:07:03,090 --> 00:07:08,090
microphone access, hotspots,
GPS tagging, and device loss.

148
00:07:08,700 --> 00:07:09,810
Now some of these should look familiar

149
00:07:09,810 --> 00:07:12,360
because we've talked about
some of these already.

150
00:07:12,360 --> 00:07:15,840
Jailbreaking is removing
the software restrictions

151
00:07:15,840 --> 00:07:18,153
imposed by the manufacturer.

152
00:07:19,080 --> 00:07:23,010
Rooting is gaining administrative
access, or root access,

153
00:07:23,010 --> 00:07:25,530
on an Android device.

154
00:07:25,530 --> 00:07:27,600
Sideloading is installing applications

155
00:07:27,600 --> 00:07:31,350
from sources other than the
authorized distribution channel,

156
00:07:31,350 --> 00:07:36,240
so from the Apple App Store or
from the Google Marketplace.

157
00:07:36,240 --> 00:07:39,300
Camera access is unauthorized video

158
00:07:39,300 --> 00:07:42,120
by malicious or unauthorized apps.

159
00:07:42,120 --> 00:07:42,990
That's a little scary,

160
00:07:42,990 --> 00:07:46,380
your phone taking pictures of
you and you don't even know.

161
00:07:46,380 --> 00:07:47,904
Same thing with your microphone,

162
00:07:47,904 --> 00:07:52,350
unauthorized recording by
malicious or unauthorized apps.

163
00:07:52,350 --> 00:07:54,960
Hotspots, so having
your phone be a hotspot,

164
00:07:54,960 --> 00:07:56,700
maybe getting unauthorized access

165
00:07:56,700 --> 00:07:58,770
'cause somebody's connecting to it.

166
00:07:58,770 --> 00:08:01,590
Also, issues of if
someone's using your data,

167
00:08:01,590 --> 00:08:03,420
maybe you're ending up with data usage

168
00:08:03,420 --> 00:08:05,223
and charges that aren't yours.

169
00:08:07,110 --> 00:08:09,210
GPS tagging, the concern there

170
00:08:09,210 --> 00:08:11,670
is it can be used to reveal your location,

171
00:08:11,670 --> 00:08:13,920
your movements, your activities,

172
00:08:13,920 --> 00:08:15,450
ultimately it could be exposure

173
00:08:15,450 --> 00:08:18,000
of vulnerable and sensitive locations.

174
00:08:18,000 --> 00:08:19,620
And then of course, device lost.

175
00:08:19,620 --> 00:08:21,150
If we lose a device,

176
00:08:21,150 --> 00:08:24,000
you know, could somebody
else get unauthorized access

177
00:08:24,000 --> 00:08:27,690
to corporate data, to personal
data, to financial accounts,

178
00:08:27,690 --> 00:08:30,240
and to any other sensitive information?

179
00:08:30,240 --> 00:08:31,830
So all things that we think about

180
00:08:31,830 --> 00:08:34,740
when we're managing a mobile device.

181
00:08:34,740 --> 00:08:37,860
And that, my friends, brings
us to a three second challenge.

182
00:08:37,860 --> 00:08:40,760
Five challenge questions, three
seconds each, let's do it.

183
00:08:41,970 --> 00:08:46,970
Extends MDM functionality
to IoT and wearables.

184
00:08:47,190 --> 00:08:49,143
One, two, three.

185
00:08:50,130 --> 00:08:53,103
That's Unified Endpoint
Management, or UEM.

186
00:08:54,690 --> 00:08:58,020
Ownership mode for a mobile
device that is company owned

187
00:08:58,020 --> 00:09:00,333
and issued for work use only.

188
00:09:01,320 --> 00:09:05,100
Company owned and issued
for work use only.

189
00:09:05,100 --> 00:09:06,753
One, two, three.

190
00:09:07,830 --> 00:09:10,983
That's gonna be COBO,
Company-issued Business Only.

191
00:09:12,570 --> 00:09:16,410
Number three, removing iOS restrictions.

192
00:09:16,410 --> 00:09:19,337
What's that called when you
remove the iOS restrictions?

193
00:09:19,337 --> 00:09:21,810
You're getting out of...

194
00:09:21,810 --> 00:09:23,793
Jail, that's jailbreaking.

195
00:09:25,380 --> 00:09:28,260
Number four, defining a virtual boundary

196
00:09:28,260 --> 00:09:30,690
around a physical area.

197
00:09:30,690 --> 00:09:32,523
One, two, three.

198
00:09:33,540 --> 00:09:35,310
That's geofencing.

199
00:09:35,310 --> 00:09:37,053
And lastly, number five,

200
00:09:38,190 --> 00:09:40,980
this can reveal your
location, your movements,

201
00:09:40,980 --> 00:09:43,200
and your activities.

202
00:09:43,200 --> 00:09:46,290
One, two, three.

203
00:09:46,290 --> 00:09:48,003
That's gonna be GPS tagging.

204
00:09:48,870 --> 00:09:51,300
All right, that brings us
to a security-in-action

205
00:09:51,300 --> 00:09:53,070
so we can apply our knowledge.

206
00:09:53,070 --> 00:09:55,623
This is about mobile device abuse.

207
00:09:56,730 --> 00:10:00,150
Pictures and videos of restricted
areas in your workplace

208
00:10:00,150 --> 00:10:03,870
are showing up online,
all your employees insist

209
00:10:03,870 --> 00:10:06,093
that they have not uploaded anything.

210
00:10:07,080 --> 00:10:09,480
The employee mobile devices were inspected

211
00:10:09,480 --> 00:10:12,240
and really nothing appears to be amiss.

212
00:10:12,240 --> 00:10:14,070
And they're adamant, your employees,

213
00:10:14,070 --> 00:10:16,500
they did not do anything.

214
00:10:16,500 --> 00:10:19,740
So what do you suspect might be going on?

215
00:10:19,740 --> 00:10:20,880
So what's going on here?

216
00:10:20,880 --> 00:10:23,970
We're getting pictures
and we're getting videos

217
00:10:23,970 --> 00:10:28,380
of restricted areas in your
workplace showing up online.

218
00:10:28,380 --> 00:10:29,970
That's pretty unnerving.

219
00:10:29,970 --> 00:10:30,803
But your employees say,

220
00:10:30,803 --> 00:10:32,070
"We have not done anything.

221
00:10:32,070 --> 00:10:34,410
Honest to God, we didn't do it."

222
00:10:34,410 --> 00:10:35,610
You looked at their devices,

223
00:10:35,610 --> 00:10:37,830
you know, you don't
see any saved pictures,

224
00:10:37,830 --> 00:10:39,510
you don't see any saved videos,

225
00:10:39,510 --> 00:10:42,660
you don't see any texts that
indicate something's going on.

226
00:10:42,660 --> 00:10:44,670
What do you suspect might be happening?

227
00:10:44,670 --> 00:10:47,220
Go ahead and put me on pause,
write down your suspicions

228
00:10:47,220 --> 00:10:48,680
or your analysis, and then...

229
00:10:49,987 --> 00:10:53,100
Well one option is unauthorized access

230
00:10:53,100 --> 00:10:54,510
to the restricted area.

231
00:10:54,510 --> 00:10:56,970
Maybe, somebody else got in there,

232
00:10:56,970 --> 00:10:59,790
not your employees, but
somebody else got in there

233
00:10:59,790 --> 00:11:02,370
and took those pictures and those videos.

234
00:11:02,370 --> 00:11:04,440
So that's one option.

235
00:11:04,440 --> 00:11:07,470
Another option is that
there's a malicious app

236
00:11:07,470 --> 00:11:09,900
has remote access to the camera

237
00:11:09,900 --> 00:11:13,620
and is responsible for taking
those photos and videos.

238
00:11:13,620 --> 00:11:15,690
Now it's quite possible
that the perpetrator

239
00:11:15,690 --> 00:11:18,570
is also deleting the photos and the video

240
00:11:18,570 --> 00:11:20,880
not to leave any kind of trail.

241
00:11:20,880 --> 00:11:22,830
So part of inspecting those devices

242
00:11:22,830 --> 00:11:24,690
would be what apps are on there,

243
00:11:24,690 --> 00:11:29,550
and are any apps having
access to the camera, right?

244
00:11:31,050 --> 00:11:33,450
Or, also, to the microphone as well,

245
00:11:33,450 --> 00:11:35,100
so you wanna take a look at that.

246
00:11:36,496 --> 00:11:38,730
Now, authorized apps
do not behave this way

247
00:11:38,730 --> 00:11:42,360
so, good chance if you have
an app that's doing this,

248
00:11:42,360 --> 00:11:44,850
that one of the devices
has been jailbroken

249
00:11:44,850 --> 00:11:47,190
or, if it's Android has been rooted.

250
00:11:47,190 --> 00:11:49,260
So you wanna take a really close look

251
00:11:49,260 --> 00:11:51,780
at do any of those devices, right?

252
00:11:51,780 --> 00:11:55,680
Have an app that has access
to the camera or video.

253
00:11:55,680 --> 00:11:58,020
And if you can out rule all of that,

254
00:11:58,020 --> 00:11:59,820
then we need to also be start thinking

255
00:11:59,820 --> 00:12:01,170
a little bit more seriously

256
00:12:01,170 --> 00:12:04,050
about the fact that maybe
there's unauthorized access

257
00:12:04,050 --> 00:12:06,060
to that restricted area.

258
00:12:06,060 --> 00:12:07,860
But doing that kind of analysis,

259
00:12:07,860 --> 00:12:09,780
thinking about all of
the different options

260
00:12:09,780 --> 00:12:12,600
and, you know, what might
have happened, as well as

261
00:12:12,600 --> 00:12:15,660
how do you remediate this
situation for the future?

262
00:12:15,660 --> 00:12:17,550
That's security-in-action.

263
00:12:17,550 --> 00:12:18,383
All right, my friends.

264
00:12:18,383 --> 00:12:20,880
Ooh, that's a big word cloud, a lot there.

265
00:12:20,880 --> 00:12:22,350
Go ahead and spend some time on this

266
00:12:22,350 --> 00:12:24,210
before you move on to the next lesson.

267
00:12:24,210 --> 00:12:26,560
But when you're ready,
I'll be waiting for you.
