CyberFortress Solutionsのハビエル・ルイス氏は、テキサス州ヒューストンに拠点を置く金融会社Apex Financial Servicesのモバイルセキュリティ対策の監査を担当しています。秘密裏に実施されたペネトレーションテストで、ハビエル氏は企業の金融システムへのアクセスに使用されている従業員の個人用スマートフォンを標的としました。彼はアクセス制御を回避する悪意のあるアプリをインストールすることで脆弱性を悪用し、機密性の高い金融データへの不正アクセスを可能にしました。デバイスにはアプリへのアクセスを制限するための具体的なセキュリティ対策がないため、この脆弱性が悪用されたのです。この脆弱性を踏まえると、Apex Financial Servicesのポリシーに最も欠けていると思われるBYODセキュリティガイドラインはどれでしょうか?
正解:A
The most likely missing BYOD guideline is reviewing application permissions before installation. In CEH mobile security guidance, a major risk in BYOD environments is the introduction of untrusted or malicious applications that abuse the mobile permission model to access corporate data, intercept authentication tokens, read storage, capture keystrokes via accessibility services, or communicate externally. When users install apps without scrutinizing requested permissions, they may unknowingly grant excessive privileges that enable data theft or access-control bypass, especially if the app leverages OS weaknesses or misconfigurations.
The scenario states Javier "installs a malicious app that bypasses access controls" and gains access to sensitive financial data because devices "lack a specific security measure to restrict app access." This maps directly to a policy gap around controlling and validating apps and their permission requests. CEH emphasizes that organizations should reduce attack surface by limiting app privileges, avoiding sideloading from untrusted sources, and enforcing least privilege through user awareness and enterprise controls such as MDM application allowlisting and permission governance. Reviewing permissions is the user-facing guideline that prevents employees from granting dangerous access (for example, SMS, storage, contacts, accessibility, device admin, or VPN configuration permissions) that can enable credential theft or unauthorized data access.
Option B adds an extra layer for local access but does not stop a malicious app with granted permissions from accessing corporate data. Option C helps if a device is physically stolen, but it does not prevent malicious apps already running under the user context. Option D protects data at rest, yet a malicious app can still exfiltrate data once it is decrypted and accessed by the user session. Therefore, permission review is the most directly relevant missing BYOD guideline.