# What is Mobile Security?

> Mobile security is the discipline of protecting smartphones, tablets, their data, applications, identities, communications, and access to organizational services throughout acquisition, enrollment, use, maintenance, loss, transfer, and disposal.

- Canonical URL: https://yellowcube.eu/glossary/mobile-security/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

It combines governance, secure configuration, authentication, application controls, encryption, update management, monitoring, response, and recovery for organization-owned and personally owned devices.

Mobile devices cross trusted and untrusted locations, use several radio interfaces, and mix work with personal activity. Protection should reflect device ownership, platform capabilities, data sensitivity, user role, connectivity, support lifetime, and the privacy implications of organizational monitoring.

### Key points

- **Establish a lifecycle:** Select supportable devices, maintain an inventory with named owners, enroll them securely, apply configurations and updates, handle loss or compromise, remove organizational access, and verify secure disposal or reuse.
- **Protect access and data:** Use strong device and service authentication, least privilege, encryption, approved applications and stores, controlled sharing, secure communications, and separation of work data where appropriate.
- **Monitor proportionately:** Assess management and update status, risky configuration, application integrity, abnormal access, and security events while collecting only telemetry justified by the purpose and ownership model.
- **Important limitation:** A device shown as enrolled, compliant, encrypted, or free of alerts is not necessarily uncompromised. Platform blind spots, delayed telemetry, malicious applications, stolen sessions, social engineering, and unsupported devices can bypass or outlast controls.

### Related terms

[Endpoint security](<https://yellowcube.eu/glossary/endpoint-security/>) · [Mobile device management (MDM)](<https://yellowcube.eu/glossary/mobile-device-management/>) · [Bring your own device (BYOD)](<https://yellowcube.eu/glossary/bring-your-own-device/>) · [Authentication](<https://yellowcube.eu/glossary/authentication/>) · [Data loss prevention (DLP)](<https://yellowcube.eu/glossary/data-loss-prevention/>) · [Mobile application security](<https://yellowcube.eu/glossary/mobile-application-security/>)

### Sources

[NIST SP 800-124 Rev. 2, Guidelines for Managing the Security of Mobile Devices in the Enterprise](https://csrc.nist.gov/pubs/sp/800/124/r2/final) · [UK NCSC, Device Security Guidance](https://www.ncsc.gov.uk/collection/device-security-guidance) · [CISA, Mobile Device Cybersecurity Checklist for Organizations](https://www.cisa.gov/sites/default/files/publications/CEG_Mobile_Device_Cybersecurity_Checklist_for_Organizations_0.pdf)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

