Effect of BYOD On Today’s Enterprise Security Systems
Files
TR Number
Date
Authors
Journal Title
Journal ISSN
Volume Title
Publisher
Abstract
This research presentation investigates the operational benefits, architectural vulnerabilities, and governance challenges associated with Bring Your Own Device (BYOD) adoption across modern enterprise environments. Motivated by the academic neglect of mobile security and informed by expert interviews at NIST and George Washington University, the study explores the organizational incentives driving BYOD—such as heightened employee productivity, cost reductions in hardware and training, work-from-anywhere flexibility, and service expansion in critical domains like healthcare and telemedicine.
However, these advantages introduce severe technical and policy complications stemming from operating system fragmentation, differing OS versions, diverse device manufacturers, and friction with legacy architectures. The analysis reveals significant security shortcomings, notably inconsistent enforcement between desktop and mobile endpoints, data leakage across shared media and cloud sync backups, improper endpoint disposal, and minimal overall management. Evaluating commercial Mobile Device Management (MDM) platforms, the authors identify a critical control gap: across 69 standard security control objectives, only 12 are universally supported across major MDM solutions, demonstrating that software platforms alone cannot fully secure personal devices.
To bridge these gaps, the presentation proposes a comprehensive security framework tailored for non-classified yet confidentiality-dependent enterprise environments. This framework balances technical controls with organizational governance, emphasizing continuous user education, rigorous compliance testing, strategic incentive structures, and sustained partnership between IT departments and end users.