ISO 27001 Mobile Device Security: Policies and Controls
Mobile devices present unique information security risks because they leave the organisation’s physical perimeter, connect to untrusted networks, and store sensitive data. Annex A.6.2 of ISO 27001:2022 directly addresses this challenge by requiring organisations to define and enforce a mobile device policy. This article explains exactly what you need to do to comply, whether you issue corporate devices or operate a BYOD model.
What Annex A.6.2 Requires for Mobile Devices
Annex A Control 6.2 – Teleworking – also cross-references mobile device security because remote working and mobile devices are tightly linked. The core requirement is that you must have a policy that governs the use of mobile devices, covering ownership models, permitted usage, software installation, network connections, and data protection. Your ISMS scope determines which devices are in scope, but any device that processes, stores, or accesses organisational information should be covered.
Essential Components of a Mobile Device Policy
Your mobile device policy must be a formal, approved document within your ISMS. The following table sets out the minimum content required to meet Annex A controls.
| Policy Component | Annex A Reference | Key Requirements |
|---|---|---|
| Device registration and inventory | A.5.9, A.8.1 | Every device must be registered, asset-tagged, and assigned to an owner |
| Approved ownership models | A.6.2 | Define BYOD, COPE, or corporate-owned; state rules for each |
| Software installation rules | A.8.20 | Only approved app stores; no sideloading; mandatory updates |
| Network connection rules | A.8.21, A.8.22 | VPN required on public Wi-Fi; no unsecured networks |
| Data storage and encryption | A.8.24 | Device encryption mandatory; containerise corporate data |
| Remote wipe and lockout | A.8.15 | Wipe on loss or theft; auto-lock after 5 minutes |
| Acceptable use | A.5.10 | No jailbreaking, no sharing credentials, no unapproved tethering |
BYOD vs Corporate-Owned: How ISO 27001 Treats Each Model
ISO 27001 does not mandate a specific ownership model, but the risks differ significantly between BYOD and corporate-owned devices. Your risk assessment must identify the specific threats for whichever model you choose.
| Factor | BYOD | Corporate-Owned |
|---|---|---|
| Cost to organisation | Low – employee bears device cost | High – organisation purchases devices |
| Employee privacy concerns | High – must separate personal and corporate data | Low – device is company property |
| Management complexity | High – mixed OS versions, personal apps | Moderate – standardised fleet |
| Wipe capability | Partial – can only wipe corporate container | Full – can wipe entire device |
| Enforcement of policy | Requires legal consent and MDM agent | Direct control via MDM |
| ISO 27001 compliance burden | Higher – more controls needed for separation | Lower – full control of device |
Mobile Device Management (MDM) Requirements Under ISO 27001
An MDM solution is not explicitly required by Annex A, but in practice it is the only way to enforce many of the controls. Your MDM should support:
- Device enrolment – automated enrolment via Apple DEP, Android Zero Touch, or Windows Autopilot
- Configuration profiles – push Wi-Fi, VPN, email, and passcode policies remotely
- Compliance rules – block devices that fail OS version, encryption, or jailbreak checks
- Application management – whitelist approved apps, blacklist prohibited ones
- Remote actions – lock, wipe, or locate lost devices
- Reporting and auditing – generate compliance reports for your internal audit programme
Application Security on Mobile Devices
Annex A.8.20 (Application Security) requires that only permitted software can run on in-scope devices. For mobile, this means:
- Apps must be installed only from official app stores (Apple App Store, Google Play, Microsoft Store)
- Sideloading must be disabled via MDM policy
- Enterprise apps must be signed and distributed through your MDM catalogue
- App permissions must be reviewed regularly – no unnecessary location, camera, or contact access
- Outdated or unsupported apps must be blocked after a defined grace period
Data Protection on Mobile Devices
Data protection controls for mobile devices fall under Annex A.8.24 (Use of Cryptography) and A.8.15 (Access Control). The following summarises the minimum cryptographic requirements.
| Data Type | Control Required | Implementation Example |
|---|---|---|
| Device-level storage | Full-disk encryption (FDE) | FileVault on macOS, BitLocker on Windows, device encryption on iOS/Android |
| Corporate data container | Container-level encryption | Microsoft Intune MAM container, VMware Workspace ONE |
| Data in transit | TLS 1.2+ mandatory | Always-on VPN certificate-based |
| Email and attachments | Client-side encryption or S/MIME | Microsoft 365 mobile with S/MIME, Outlook with MAM policy |
| Cloud-synced data | Managed by conditional access | Block sync to personal cloud accounts via MDM |
Remote Wipe and Loss Prevention
Annex A.8.15 (Access Control) and A.8.16 (Identity Management) require that access can be revoked instantly when a device is lost or the employee leaves. Your policy must include:
- Automatic triggers – remote wipe activates after 10 failed passcode attempts
- Geofencing – optionally wipe if device leaves a defined geographic area
- Selective wipe – for BYOD, remove only the corporate container
- Full wipe – for corporate devices, reimage to factory settings
- Reporting – log all wipe events and notify the security team within 1 hour
Acceptable Use and User Responsibilities
Your acceptable use policy (Annex A.5.10) must cover mobile-specific behaviours. Users must acknowledge the policy annually:
- Devices must not be jailbroken or rooted
- Passcodes or biometric authentication must be enabled at all times
- Devices must not be left unattended in public places
- Lost or stolen devices must be reported within 1 hour
- Personal use must not interfere with security controls
- Corporate data must not be transferred to personal cloud accounts
Frequently Asked Questions
Does ISO 27001 require every employee to use a corporate phone?
No. ISO 27001 allows BYOD, COPE, and corporate-owned models. What matters is that your policy defines the chosen model and that your controls adequately address the specific risks of that model.
Do we need an MDM to pass ISO 27001 certification?
The standard does not mandate any specific technology, but an MDM is the most practical way to demonstrate compliance with controls around configuration, compliance checking, and remote wipe. An auditor will expect to see how you enforce policy on mobile devices.
How do we handle personal data on BYOD devices under ISO 27001?
Use containerisation or application management to separate corporate data from personal data. Your policy must state that the organisation only manages the corporate container and that personal data remains private. Ensure your consent agreement is signed before enrolling any BYOD device.
What happens if an employee refuses to install MDM on their personal phone?
Your policy should offer alternatives: a corporate device, a stipend for a separate work phone, or limiting the employee’s role to tasks that do not require mobile access to corporate data. Blanket refusal without accommodation may constitute a non-compliance you must treat through your disciplinary process.
Is mobile device security part of the ISO 27001 Statement of Applicability?
Yes. You must list A.6.2 (and related controls such as A.8.15, A.8.20, and A.8.24) in your Statement of Applicability and justify their inclusion or exclusion based on your risk assessment.
How often should we review our mobile device policy?
At least annually as part of your ISMS management review, and additionally whenever there is a significant change in mobile OS versions, a major security incident, or a change in your device ownership model.
Ready to implement or audit ISO 27001 mobile device security? Our ISMS consultants help you build policies, select MDM solutions, and prepare for certification. Contact Bitrixme today for a free 30-minute consultation.