iso-27001-mobile-device-security

By July 25th, 2026compliant-growth7 min read

ISO 27001 Mobile Device Security: Policies and Controls

Mobile devices present unique information security risks because they leave the organisation’s physical perimeter, connect to untrusted networks, and store sensitive data. Annex A.6.2 of ISO 27001:2022 directly addresses this challenge by requiring organisations to define and enforce a mobile device policy. This article explains exactly what you need to do to comply, whether you issue corporate devices or operate a BYOD model.

What Annex A.6.2 Requires for Mobile Devices

Annex A Control 6.2 – Teleworking – also cross-references mobile device security because remote working and mobile devices are tightly linked. The core requirement is that you must have a policy that governs the use of mobile devices, covering ownership models, permitted usage, software installation, network connections, and data protection. Your ISMS scope determines which devices are in scope, but any device that processes, stores, or accesses organisational information should be covered.

Essential Components of a Mobile Device Policy

Your mobile device policy must be a formal, approved document within your ISMS. The following table sets out the minimum content required to meet Annex A controls.

Policy ComponentAnnex A ReferenceKey Requirements
Device registration and inventoryA.5.9, A.8.1Every device must be registered, asset-tagged, and assigned to an owner
Approved ownership modelsA.6.2Define BYOD, COPE, or corporate-owned; state rules for each
Software installation rulesA.8.20Only approved app stores; no sideloading; mandatory updates
Network connection rulesA.8.21, A.8.22VPN required on public Wi-Fi; no unsecured networks
Data storage and encryptionA.8.24Device encryption mandatory; containerise corporate data
Remote wipe and lockoutA.8.15Wipe on loss or theft; auto-lock after 5 minutes
Acceptable useA.5.10No jailbreaking, no sharing credentials, no unapproved tethering

BYOD vs Corporate-Owned: How ISO 27001 Treats Each Model

ISO 27001 does not mandate a specific ownership model, but the risks differ significantly between BYOD and corporate-owned devices. Your risk assessment must identify the specific threats for whichever model you choose.

FactorBYODCorporate-Owned
Cost to organisationLow – employee bears device costHigh – organisation purchases devices
Employee privacy concernsHigh – must separate personal and corporate dataLow – device is company property
Management complexityHigh – mixed OS versions, personal appsModerate – standardised fleet
Wipe capabilityPartial – can only wipe corporate containerFull – can wipe entire device
Enforcement of policyRequires legal consent and MDM agentDirect control via MDM
ISO 27001 compliance burdenHigher – more controls needed for separationLower – full control of device

Mobile Device Management (MDM) Requirements Under ISO 27001

An MDM solution is not explicitly required by Annex A, but in practice it is the only way to enforce many of the controls. Your MDM should support:

  • Device enrolment – automated enrolment via Apple DEP, Android Zero Touch, or Windows Autopilot
  • Configuration profiles – push Wi-Fi, VPN, email, and passcode policies remotely
  • Compliance rules – block devices that fail OS version, encryption, or jailbreak checks
  • Application management – whitelist approved apps, blacklist prohibited ones
  • Remote actions – lock, wipe, or locate lost devices
  • Reporting and auditing – generate compliance reports for your internal audit programme

Application Security on Mobile Devices

Annex A.8.20 (Application Security) requires that only permitted software can run on in-scope devices. For mobile, this means:

  • Apps must be installed only from official app stores (Apple App Store, Google Play, Microsoft Store)
  • Sideloading must be disabled via MDM policy
  • Enterprise apps must be signed and distributed through your MDM catalogue
  • App permissions must be reviewed regularly – no unnecessary location, camera, or contact access
  • Outdated or unsupported apps must be blocked after a defined grace period

Data Protection on Mobile Devices

Data protection controls for mobile devices fall under Annex A.8.24 (Use of Cryptography) and A.8.15 (Access Control). The following summarises the minimum cryptographic requirements.

Data TypeControl RequiredImplementation Example
Device-level storageFull-disk encryption (FDE)FileVault on macOS, BitLocker on Windows, device encryption on iOS/Android
Corporate data containerContainer-level encryptionMicrosoft Intune MAM container, VMware Workspace ONE
Data in transitTLS 1.2+ mandatoryAlways-on VPN certificate-based
Email and attachmentsClient-side encryption or S/MIMEMicrosoft 365 mobile with S/MIME, Outlook with MAM policy
Cloud-synced dataManaged by conditional accessBlock sync to personal cloud accounts via MDM

Remote Wipe and Loss Prevention

Annex A.8.15 (Access Control) and A.8.16 (Identity Management) require that access can be revoked instantly when a device is lost or the employee leaves. Your policy must include:

  • Automatic triggers – remote wipe activates after 10 failed passcode attempts
  • Geofencing – optionally wipe if device leaves a defined geographic area
  • Selective wipe – for BYOD, remove only the corporate container
  • Full wipe – for corporate devices, reimage to factory settings
  • Reporting – log all wipe events and notify the security team within 1 hour

Acceptable Use and User Responsibilities

Your acceptable use policy (Annex A.5.10) must cover mobile-specific behaviours. Users must acknowledge the policy annually:

  • Devices must not be jailbroken or rooted
  • Passcodes or biometric authentication must be enabled at all times
  • Devices must not be left unattended in public places
  • Lost or stolen devices must be reported within 1 hour
  • Personal use must not interfere with security controls
  • Corporate data must not be transferred to personal cloud accounts

Frequently Asked Questions

Does ISO 27001 require every employee to use a corporate phone?

No. ISO 27001 allows BYOD, COPE, and corporate-owned models. What matters is that your policy defines the chosen model and that your controls adequately address the specific risks of that model.

Do we need an MDM to pass ISO 27001 certification?

The standard does not mandate any specific technology, but an MDM is the most practical way to demonstrate compliance with controls around configuration, compliance checking, and remote wipe. An auditor will expect to see how you enforce policy on mobile devices.

How do we handle personal data on BYOD devices under ISO 27001?

Use containerisation or application management to separate corporate data from personal data. Your policy must state that the organisation only manages the corporate container and that personal data remains private. Ensure your consent agreement is signed before enrolling any BYOD device.

What happens if an employee refuses to install MDM on their personal phone?

Your policy should offer alternatives: a corporate device, a stipend for a separate work phone, or limiting the employee’s role to tasks that do not require mobile access to corporate data. Blanket refusal without accommodation may constitute a non-compliance you must treat through your disciplinary process.

Is mobile device security part of the ISO 27001 Statement of Applicability?

Yes. You must list A.6.2 (and related controls such as A.8.15, A.8.20, and A.8.24) in your Statement of Applicability and justify their inclusion or exclusion based on your risk assessment.

How often should we review our mobile device policy?

At least annually as part of your ISMS management review, and additionally whenever there is a significant change in mobile OS versions, a major security incident, or a change in your device ownership model.


Ready to implement or audit ISO 27001 mobile device security? Our ISMS consultants help you build policies, select MDM solutions, and prepare for certification. Contact Bitrixme today for a free 30-minute consultation.