TechKnowSurge
VideoSecurityFree

Device Deployment Models

Mobile device deployment models define how organizations provision, own, and control the devices employees use for work, each carrying distinct trade-offs between security, cost, and usability. The four primary models are corporate-owned, choose your own device (CYOD), corporate-owned personally enabled (COPE), and bring your own device (BYOD).

Complete this video to capture a CTF flag worth 1 point.

About this video

The way organizations deploy and manage devices has grown substantially more complex as the workforce has become mobile, remote, and increasingly reliant on personally owned technology. Where desktop computers once stayed physically within a secured office network, employees now routinely access corporate systems from laptops, smartphones, and tablets in locations entirely outside organizational control. This shift demands deliberate policy decisions about who owns devices, who pays for them, and what level of personal use is permitted, because each of those choices directly shapes the organization's security posture and support burden. At one end of the spectrum, fully corporate-owned deployments give IT teams maximum control. The organization selects, purchases, and manages a standardized set of hardware, making it straightforward to enforce consistent patching cycles, data loss prevention policies, and access controls. The trade-off is reduced employee autonomy, which can lower satisfaction and push some users toward unauthorized workarounds. CYOD, or choose your own device, maintains corporate ownership while allowing employees to select from a pre-approved list of hardware, improving familiarity and productivity while keeping the supported device catalog manageable. COPE, corporate-owned personally enabled, goes a step further by allowing employees to use company hardware for personal activities, eliminating the burden of carrying two devices and increasing adoption, though it introduces the risk of policy abuse and blurred boundaries between personal and professional data. BYOD, bring your own device, places ownership and purchase responsibility on the employee, sometimes offset by a stipend. This model can reduce capital costs for the organization and improve ease of use since employees work on hardware they already know well. However, it significantly complicates security enforcement, as IT teams have limited visibility and control over devices they do not own. Questions around data residency, acceptable-use enforcement, and privacy become harder to resolve, and integrating personally owned devices with corporate systems often increases rather than decreases the support burden. Selecting the right deployment model requires balancing these operational and security realities against the organization's risk tolerance, workforce needs, and available IT resources.

What you'll learn

What's covered

Mobile Device Deployment Models

Key terms

Corporate-Owned
A mobile device deployment model in which the organization purchases and owns all devices, retaining full control over security configurations, updates, and permitted uses.
Choose Your Own Device
CYOD
Choose Your Own Device is a mobile device policy that allows employees to select from a pre-approved list of devices, each enrolled under organizational security management policies.
Corporate Owned, Personally Enabled
COPE
Corporate Owned, Personally Enabled is a mobile device policy where the organization provides and manages the device while permitting limited personal use, balancing control with employee flexibility.
Bring Your Own Device
BYOD
Bring Your Own Device is a policy that permits employees to use personal devices to access corporate systems and data, introducing security challenges around data segregation, device management, and policy enforcement.
Data Loss Prevention
DLP
A set of tools and processes designed to detect and prevent unauthorized access, use, or transmission of sensitive data.
Shadow IT
The use of unauthorized software, systems, or services within an organization without IT department knowledge or approval. Shadow IT creates security blind spots because unmanaged assets fall outside standard patching, monitoring, and access controls.
Attack Surface
The total set of points in a system where an unauthorized user can attempt to enter or extract data.
Patch Management
The process of acquiring, testing, and installing software updates to fix vulnerabilities and improve functionality.

Topics

Mobile Device Management Byod Cope Cyod Endpoint Security Mobile Security

Transcript

One of the first things that we need to determine is what devices are going to be allowed within our organization and how we are going to deploy those.

What has changed

Now, at one point in time, most of our devices were pretty straightforward on how we were going to manage them. We had things like desktops, and people reported into the office. They showed up in the office, and then they couldn't take this desktop home, so everything was secure within the network. It was pretty straightforward that the company would buy these desktops, install the desktops, take care of a lot of the security aspects of these desktops, and it wouldn't leave the building. So device security was much simpler.

But some things have changed. Number one is that we've improved technology, so things are much more mobile now and we can take them with us. Number two is that there are a lot of devices in consumers' hands now — people own a lot more technology than they used to. And another thing that's changed is that a lot more people are working from home or remotely or traveling, and so we have a much more diverse area of equipment that we need to support, and how we support it. This introduces a lot of security concerns.

Not allowing the devices at all

How are we going to tackle these security concerns? One thing we could do is just say that these devices are not allowed. That would be the most secure, and it's perfectly acceptable in some companies. For instance, if you had a bank branch office that was making sensitive financial transactions, you wouldn't want that to be in a laptop form that an employee would take home with them. That just wouldn't be something that would be acceptable. It needs to be on something that is on that network, that is not going to be moved around or gone anywhere else. It can't be mobile. So this is an acceptable solution for many businesses.

But for many businesses it's not going to be, because there are going to be people that are going to be working from home or traveling, or they're going to have their phones and they need to check email or make phone calls on that phone when they're out and about.

Who owns the device?

So then the next question is, does the company purchase that, does the organization purchase that, or are they going to make their employees purchase that? Is it personally owned or corporate owned? If it's corporate owned, then are they going to allow the employees to make personal phone calls on those mobile devices, or use it for doing personal business? So there are a lot of questions to be asked when we're deploying these mobile devices.

There are some acronyms that you need to be aware of:

  • If it's corporate owned, then the company purchases and owns those.
  • If it is corporate owned and we decide to do choose your own device, then that means the employees can actually choose those devices, and they have a selection of which devices they want to choose from.
  • If it's corporately owned, personally enabled, then what we're saying is we're allowing our end users to be able to use that for personal use as well.
  • And then there's also bring your own device, where the employees can purchase that equipment and then they will use it for business needs, and maybe they get an allowance for that, maybe not.

So there are some deployment models that we can implement when we're deploying these. Each one of these models has its pros and cons, especially from a security perspective.

Corporate owned

If it's corporate owned, this is great because we have a lot of security control over it. We can implement things like data loss prevention to make sure that nothing sensitive is getting downloaded on this device. We can make sure we manage the updates and patches that happen on this phone. And it's easier to support, because we only have certain models that we are supporting, so it's very limited in scope on what we have to support.

Of course, some of it could be harder to manage. That is, if we are managing all these extra devices rather than just letting the end user manage them, that could create some problems with management of them. There could also be less employee satisfaction, when they have to be kind of railroaded in, or have to conform to what the company wants them to use and operate. So there are some employee satisfaction concerns over it as well.

Choose your own device

This could be employee owned, but we could allow the employees to choose their own device. This makes it easier for them to use, because they get a choice, which possibly increases their satisfaction with it. It could be easier to support, because now they could choose a phone or mobile device that they are more familiar with. It could increase their productivity, because if we're choosing products that are more in line with what they want, they could be more efficient with using those products.

It also reduces shadow IT. A lot of times, if you are providing certain models of phones for the employees that they're not happy with, they'll go around it and start doing their own thing. So by allowing them to choose the device, it reduces that shadow IT.

It can be difficult to support, because now you're increasing how many models and how many different devices that you have to support, because you're giving them an option.

Corporate owned, personally enabled

Now, whether we're allowing them to choose their own device or not, the other decision we have to make is, is it going to be personally enabled? So this is corporate owned, personally enabled, which means that we're allowing them to use it for personal use. If we don't allow them to use it for personal use, then maybe, if it's a cell phone that they have to carry on them, now they have to carry two cell phones, because they've got their personal cell phone and they've got the business one. So that one doesn't really lead to ease of use.

But if we allow them to personally enable this, it allows them to have ease of use. It also could be easier to support, because now it's all in one phone. And there could be higher employee satisfaction, because now they don't have to carry two devices, and increased productivity, because now, when they're carrying it around, they have everything available for them to answer email and do everything on this device. So it really just makes it easier for the end user to use this device and be able to do everything that they want to do on it.

But there could be a decrease in productivity as well, because if they've got their personal stuff on this phone, are they going to be using that personal stuff at work? There's also a lot of potential for abuse, for them installing applications or overusing certain things on the phone that they normally wouldn't use if we didn't allow them to do personal business on it.

Bring your own device

Taking this to the next level, we have bring your own device, where you're either allowing or requiring employees to purchase their own equipment. Maybe they give a stipend for this, where it's some money that they can go and purchase their own equipment, or maybe they don't give any kind of allowance for that.

This allows for ease of use for the end user, and ease of support, because they know their own equipment. There are some cost savings to the company, because they don't have to purchase this. And there could be increased productivity, because now the employee is just managing their own stuff. But there also could be decreased productivity, because here again, are they doing personal stuff on these devices, and are they doing that during working hours, when they are supposed to be working?

It also can be difficult to support. It could be easy to support because they know their own equipment, but if they're trying to integrate it into some of the company's systems, then that could be more difficult to support, because now we're trying to help them out on equipment we're not familiar with.

There are also very little security controls with this. There are some ways that we can implement some level of security on it, but there are some security control considerations. What does the data security look like? What about the privacy concerns with it? And then it also just increases complexity. So how are we going to make sure that security is managed on these devices as they connect into our network?

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →