Mobile device deployment models define how organizations provision, own, and control the devices employees use for work, each carrying distinct trade-offs between security, cost, and usability. The four primary models are corporate-owned, choose your own device (CYOD), corporate-owned personally enabled (COPE), and bring your own device (BYOD).
Mobile Device Deployment Models
One of the first things that we need to determine is what devices are going to be allowed within our organization and how we are going to deploy those.
Now, at one point in time, most of our devices were pretty straightforward on how we were going to manage them. We had things like desktops, and people reported into the office. They showed up in the office, and then they couldn't take this desktop home, so everything was secure within the network. It was pretty straightforward that the company would buy these desktops, install the desktops, take care of a lot of the security aspects of these desktops, and it wouldn't leave the building. So device security was much simpler.
But some things have changed. Number one is that we've improved technology, so things are much more mobile now and we can take them with us. Number two is that there are a lot of devices in consumers' hands now — people own a lot more technology than they used to. And another thing that's changed is that a lot more people are working from home or remotely or traveling, and so we have a much more diverse area of equipment that we need to support, and how we support it. This introduces a lot of security concerns.
How are we going to tackle these security concerns? One thing we could do is just say that these devices are not allowed. That would be the most secure, and it's perfectly acceptable in some companies. For instance, if you had a bank branch office that was making sensitive financial transactions, you wouldn't want that to be in a laptop form that an employee would take home with them. That just wouldn't be something that would be acceptable. It needs to be on something that is on that network, that is not going to be moved around or gone anywhere else. It can't be mobile. So this is an acceptable solution for many businesses.
But for many businesses it's not going to be, because there are going to be people that are going to be working from home or traveling, or they're going to have their phones and they need to check email or make phone calls on that phone when they're out and about.
So then the next question is, does the company purchase that, does the organization purchase that, or are they going to make their employees purchase that? Is it personally owned or corporate owned? If it's corporate owned, then are they going to allow the employees to make personal phone calls on those mobile devices, or use it for doing personal business? So there are a lot of questions to be asked when we're deploying these mobile devices.
There are some acronyms that you need to be aware of:
So there are some deployment models that we can implement when we're deploying these. Each one of these models has its pros and cons, especially from a security perspective.
If it's corporate owned, this is great because we have a lot of security control over it. We can implement things like data loss prevention to make sure that nothing sensitive is getting downloaded on this device. We can make sure we manage the updates and patches that happen on this phone. And it's easier to support, because we only have certain models that we are supporting, so it's very limited in scope on what we have to support.
Of course, some of it could be harder to manage. That is, if we are managing all these extra devices rather than just letting the end user manage them, that could create some problems with management of them. There could also be less employee satisfaction, when they have to be kind of railroaded in, or have to conform to what the company wants them to use and operate. So there are some employee satisfaction concerns over it as well.
This could be employee owned, but we could allow the employees to choose their own device. This makes it easier for them to use, because they get a choice, which possibly increases their satisfaction with it. It could be easier to support, because now they could choose a phone or mobile device that they are more familiar with. It could increase their productivity, because if we're choosing products that are more in line with what they want, they could be more efficient with using those products.
It also reduces shadow IT. A lot of times, if you are providing certain models of phones for the employees that they're not happy with, they'll go around it and start doing their own thing. So by allowing them to choose the device, it reduces that shadow IT.
It can be difficult to support, because now you're increasing how many models and how many different devices that you have to support, because you're giving them an option.
Now, whether we're allowing them to choose their own device or not, the other decision we have to make is, is it going to be personally enabled? So this is corporate owned, personally enabled, which means that we're allowing them to use it for personal use. If we don't allow them to use it for personal use, then maybe, if it's a cell phone that they have to carry on them, now they have to carry two cell phones, because they've got their personal cell phone and they've got the business one. So that one doesn't really lead to ease of use.
But if we allow them to personally enable this, it allows them to have ease of use. It also could be easier to support, because now it's all in one phone. And there could be higher employee satisfaction, because now they don't have to carry two devices, and increased productivity, because now, when they're carrying it around, they have everything available for them to answer email and do everything on this device. So it really just makes it easier for the end user to use this device and be able to do everything that they want to do on it.
But there could be a decrease in productivity as well, because if they've got their personal stuff on this phone, are they going to be using that personal stuff at work? There's also a lot of potential for abuse, for them installing applications or overusing certain things on the phone that they normally wouldn't use if we didn't allow them to do personal business on it.
Taking this to the next level, we have bring your own device, where you're either allowing or requiring employees to purchase their own equipment. Maybe they give a stipend for this, where it's some money that they can go and purchase their own equipment, or maybe they don't give any kind of allowance for that.
This allows for ease of use for the end user, and ease of support, because they know their own equipment. There are some cost savings to the company, because they don't have to purchase this. And there could be increased productivity, because now the employee is just managing their own stuff. But there also could be decreased productivity, because here again, are they doing personal stuff on these devices, and are they doing that during working hours, when they are supposed to be working?
It also can be difficult to support. It could be easy to support because they know their own equipment, but if they're trying to integrate it into some of the company's systems, then that could be more difficult to support, because now we're trying to help them out on equipment we're not familiar with.
There are also very little security controls with this. There are some ways that we can implement some level of security on it, but there are some security control considerations. What does the data security look like? What about the privacy concerns with it? And then it also just increases complexity. So how are we going to make sure that security is managed on these devices as they connect into our network?
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →