- Mobile Device Management (MDM) is a crucial tool for managing, securing, and enforcing ISO 27001-compliant security policies on mobile devices within enterprises.
- MDM provides key functions such as device monitoring, policy enforcement, software distribution, and encryption to protect sensitive business data and mitigate security risks.
- ISO 27001:2022 addresses mobile devices in Annex A control 8.1 User endpoint devices; access control and cryptography sit in 5.15 to 5.18, 8.2 to 8.5, and 8.24.
- Deeploi.io enhances Kertos’ ISO 27001 software with comprehensive MDM features, enabling easy and standardized management of encryption, access rights, and security policies on mobile devices.
Mobile Work: How Companies Can Leverage Opportunities and Minimize Risks with Mobile Device Management.
In recent years, mobile devices have taken on an unmistakable presence in the corporate world. The widespread adoption of mobile devices in enterprises got a boost with the COVID-led remote working trend gaining traction. Employees' move to mobile technology has transformed how organizations function, resulting in improved workflows, communications, flexibility, mobility, and efficiency.
Real-time data access and collaboration enabled by mobile devices have accelerated teamwork. With smartphones, tablets, laptops, and even wearables becoming an integral part of most organizations, it's essential to weigh the trade-off in terms of risks. Because enterprise mobile devices access sensitive business data, they can threaten security if they are lost, hacked, or stolen.
These endpoints can work as entry points for attackers and can potentially compromise the entire IT infrastructure if adequate security measures are not in place. If sensitive business data is compromised, organizations also risk scrutiny of data protection regulations, which mandate strict protocols for safeguarding personal information.
That's where mobile device management (MDM) steps in as a critical safeguard for organizational data. As the landscape of security threats and regulatory enforcement has evolved, IT and security leaders are now tasked with provisioning, managing, and securing mobile devices within their corporate environments. MDM, essentially, controls and secures a wide variety of mobile devices used in the workplace.
What is mobile device management (MDM)?
Mobile device management is a set of software solutions and strategies, including on-device applications and configurations, corporate policies, and backend infrastructure. It allows IT to automate, secure, and enforce policies on mobile devices connected to an organization's network, simplifying the IT management of end user devices.
The roots of MDM go back to the early 2000s, when the first wave of mobile devices, especially the launch of Apple's first iPhone in 2007, hit the enterprise realm. The recent Bring Your Own Device (BYOD) trend that has left organizations vulnerable to issues with shadow IT has further snowballed the importance of mobile device management.
Key features and components of mobile device management
Device monitoring
In an MDM program, dedicated work devices are assigned to each employee. These devices have an MDM agent installed that connects them directly with the MDM server. The MDM server collects a host of data about devices, including real-time GPS location, usage statistics, malware detection, and compliance with organizational and industry policies.
Every time an unauthorized access is attempted, unapproved applications are installed, or policies are violated, the MDM agent triggers an alert to notify IT administrators. Device monitoring is also useful in emergencies when an employee loses a device and needs help recovering it.
Policy enforcement
An effective MDM solution enables administrators to set rules that coincide with their organizational objectives. These rules, as part of policy enforcement, ensure that mobile devices that are part of organizational assets or have access to sensitive data adhere to corporate policies.
These policies include management of applications, networks, and content; implementation of security measures such as password policies, remote wipes, and lock functionalities; provision of access controls as per roles and responsibilities; and monitoring and reporting of compliance.
Software distribution
The MDM software distribution feature allows administrators to remotely deploy, update, and manage applications on mobile devices. MDM allows integration with both app stores, like the Apple App Store and Google Play Store, and enterprise app stores for seamless app distribution and updates.
As the policy allows, admins can remotely push the applications to install on managed devices, either with user consent or without their intervention. It ensures all applications across managed devices are running updated versions of applications, and if need be, they could be rolled back to the previous version. This feeds directly into Annex A control 8.19 Installation of software on operational systems, which governs who may install what and calls for allow or deny listing.
Basics of ISO 27001
In this digital age, where data is the new currency, its privacy and security are top priorities for organizations worldwide. If an organization's ISMS is compromised, it risks losing valuable information assets, which can result in reputational and financial damages. To help organizations, the internationally recognized ISO 27001 standard provides a robust framework for the information security risk management process. It thereby helps organizations minimize the security gaps that could lead to unauthorized access, disclosure, alteration, or destruction of sensitive information.
ISO 27001 is an international standard for information security management published by the ISO in collaboration with the IEC, a leading international organization that develops international standards. It provides a framework for requirements for defining, implementing, operating, and improving an organization's information security management system (ISMS).
Compliance with ISO 27001 demonstrates the organization's commitment to information security. ISO 27001 certification eases companies' compliance with data protection regulations like the GDPR, gives them a competitive edge in the international marketplace, and makes them trusted by clients and stakeholders.
Main components and structures of the standard
As a member of the ISO 27000 series, ISO 27001 is the most commonly certified standard. Its popularity and effectiveness have led to many organizations adopting it for their IT governance, risk management, and compliance programs. Compliance with ISO 27001, and therefore maintaining a strong ISMS, requires a structured approach. One such approach is the Plan-Do-Check-Act (PDCA) cycle.
- Plan: Laying the foundation
The plan phase begins with setting clear objectives for ISMS, which should be in alignment with the organization's strategic goals. Objectives for organizations can vary depending on whether they're aiming to comply with regulatory requirements, protect sensitive data, or improve their overall cybersecurity posture.
This step involves conducting a comprehensive risk assessment of the ISMS. It helps organizations identify threats and vulnerabilities unique to them in terms of system characteristics, management, complexity, people, technology in place, etc. It thereby lays the foundation for selecting and implementing the appropriate security controls as mentioned under the ISO 27001 framework.
- Do: Turning plans into action
The Do phase involves developing and enforcing ISMS policies, deploying security software, and providing training to employees. It requires organizations to conduct risk assessments and evaluate the reasons behind each structure. This phase includes the preparation of procedures that address identified risks and the implementation of appropriate security controls.
- Check: Continuous monitoring and review
Maintaining optimal performance is a must to ensure the results of processes are within the expected range. This phase covers monitoring, measuring, analysis, and evaluation checks of the implemented controls against the defined policies and objectives. Continuous monitoring of the key performance indicators (KPIs) provides valuable insights into the health of the ISMS and helps identify, treat, eliminate, or improve the detected issues.
- Act: Updates and improvements to the ISMS
The final phase in the PDCA cycle, Act, is about taking corrective actions based on findings from the Check phase to achieve continual improvement of the ISMS. Insights derived from the Check phase may require organizations to invest additional working hours or even redesign the existing system (in the worst cases). Based on risk assessment, organizations can prioritize which gaps to tackle immediately and which ones to hold for later. The PDCA cycle is a closed loop that requires dynamic improvement over time.
Mobile device management is a good example of a control where the policy is not the point. Miriam Mindt explains what evidence an auditor wants for a control, and why the document is only the start.
Connection between MDM and ISO 27001
As threats became more sophisticated, ISO/IEC released a new version of ISO 27001 in 2022, reflecting the need to secure mobile devices and form policies around their use. Annex A of ISO 27001:2022 holds 93 controls in four themes: 37 organizational (5.1 to 5.37), 8 people (6.1 to 6.8), 14 physical (7.1 to 7.14), and 34 technological (8.1 to 8.34). Mobile device management (MDM) best practices touch the following clause and controls.
One note for anyone reconciling this against older documentation: the 2013 numbering, which put access control under A.9 and cryptography under A.10, no longer applies. The transition period ended on 31 October 2025, and certificates issued against the old version have been invalid since.
Information security policies (Clause 5.2 and Annex A 5.1)
Clause 5.2 of ISO 27001 requires top management in an organization to establish an information security policy. It's one of the first documents an organization needs to create when building their ISMS. As an Annex A control, the documented version is 5.1 Policies for information security. This policy communicates the purposes and impact of information security to all staff members. When formally communicated, the policy provides a clear vision and direction, helping everyone to understand the organization's objectives and strategic approach to information security.
MDM solutions allow organizations to draft policies related to security, such as mandatory encryption, password policies, access controls, etc. These policies are applied across all mobile devices, ensuring they comply with the organization's security standards. MDM provides a centralized view of all devices' performances and monitors compliance with corporate policies.
It enables organizations to manage security settings across all mobile devices from a single platform and enforce secure configurations on devices of concern. Push notification features on MDM platforms allow organizations to directly manage updates of software on user devices and convey any information as a notification that could be important for users' following best practices.
User endpoint devices (Annex A 8.1)
Annex A 8.1 User endpoint devices is the control that took the place of the 2013 mobile device policy. It requires that information stored on, processed by, or accessible through an endpoint is protected, whether the device belongs to the company or to the employee. That makes it the control an MDM rollout is measured against most directly.
Four things get checked on endpoints in practice: hard disk encryption, screen lock, password manager, and antivirus. Device enrollment and inventory, separation of business and private data under BYOD, and remote wipe of lost devices come on top of those. All of these settings can be applied centrally through MDM and exported as a configuration report. For an auditor, the policy is only the start: what has to be evidenced is the state of the devices, not the document.
Access control (Annex A 5.15 to 5.18 and 8.2 to 8.5)
What the 2013 version carried as chapter A.9 with 14 controls is spread across nine controls in two themes in ISO 27001:2022: 5.15 Access control, 5.16 Identity management, 5.17 Authentication information, and 5.18 Access rights on the organizational side, plus 8.2 Privileged access rights, 8.3 Information access restriction, 8.4 Access to source code, 8.5 Secure authentication, and 8.18 Use of privileged utility programs on the technological side. Mobile device management contributes to a good part of them.
- Setting the rules (5.15): 5.15 requires rules for physical and logical access derived from the organization's requirements, together with documented roles and responsibilities. MDM solutions express those rules as policies for application management, content control, and access rights, and enforce them on the device.
- Managing identities and rights (5.16 and 5.18): The full lifecycle of an identity, from creation through change to removal, belongs to 5.16; the granting, review, and revocation of access rights to 5.18. Both sides count as evidence: the list of every account with access to a resource, its privileges, and when and by whom access was granted, and the recurring review that detects deviations from role-based access.
- Authentication (5.17 and 8.5): 5.17 governs how authentication information is allocated and managed, meaning passwords, tokens, and keys; 8.5 governs the secure log-on itself. MDM enforces password policies, screen locks, and multi-factor authentication on the device, and uses notifications to keep users aware of their obligations.
- Restricting access (8.2, 8.3, and 8.4): 8.3 restricts access to information and applications to what the role requires, 8.2 handles privileged accounts separately, and 8.4 covers access to source code. On managed endpoints, MDM platforms enforce these restrictions through configuration profiles, app allow lists, and containerization.
Use of cryptography (Annex A 8.24)
Annex A 8.24 Use of cryptography merges what the 2013 version split across two controls: the policy on the use of cryptographic controls, and key management. Its objective is to put effective cryptographic and encryption controls in place to ensure the confidentiality, authenticity, and integrity of business information. Policy creation on the use of encryption helps identify business requirements where encryption can be vital to implement.
It's important to select the right cryptographic technologies and techniques; otherwise, poor choice and management of cryptographic materials (e.g., keys and certificates) can themselves lead to vulnerabilities in the system. Often, the management of key materials is the weakest point, so having robust and secure processes around them, from their creation, distribution, changes, backup, and storage to their destruction, is crucial in maintaining the security of the system.
MDM enables organizations to enforce encryption on mobile devices. It includes the compulsory encryption of data at rest and in transit, as well as configuring devices with organization-approved cryptographic standards. A good MDM solution provides configuration options for FileVault, which encrypts the entire contents of a Mac's hard drive using encryption methods like XTS-AES-128.
Secure management of cryptographic keys ensures controlled generation, distribution, and storage. With the escrowing key feature, even if the primary key is lost or forgotten, it is possible to decrypt data with the recovery key available.
Deeploi.io as an MDM integration for ISO 27001
At Kertos, we help companies transform data protection into actual compliance. No matter the amount of data or complexity within an organization's privacy processes, Kertos.io always delivers. Our ISO 27001 software comprises various tools and mechanisms that make your ISMS management and enhancement as easy as pie.
To make your company ISO 27001-compliant, we're equipped with the best tools in our arsenal. Only the MDM integration missing so far has been achieved with our partnership with Deeploi.io, which boosts our ISO 27001 certification capabilities.
The comprehensive MDM capabilities offered by Deeploi enable organizations to enforce security policies in line with ISO 27001 requirements across all mobile devices. With the best encryption techniques, it ensures that your sensitive information data is protected as per ISO 27001 standards, whether at rest or in transit. For more information on how we can help you with MDM integration for ISO 27001 compliance, contact us today.





