M-RAM: a Mobile Risk Assessment Method for Enterprise Mobile Security

Publication date

2019

Authors

Janssen, Joey
Spruit, MarcoISNI 0000000077172004

Editors

Advisors

Supervisors

DOI

Document Type

Report
Open Access logo

License

Abstract

Mobile solutions seem to outrun the control and governance within enterprise organizations. The acceptance of smartphones and tablets in business has gone at such a high pace that organizations are no longer able to oversee the risks of their mobile usage. Traditional risk assessment methods do not consider usage of mobile devices— mobility—despite the fact that enterprise organizations struggle with managing mobile risks. We aim to fill this gap by introducing a Mobile Risk Assessment Method (M-RAM). The method is based on an evaluation of industry standard risk methods and 22 interviews with mobile security experts. Three components compose the method: (1) a risk assessment process that is customized for mobility, (2) involved entities that oppose risks, and (3) attention areas that can contain vulnerabilities as well as controls. Moreover, the study provides a practical work program to conduct the M-RAM and validates the approach by conducting a case study.

Keywords

mobile risks, enterprise mobility, mobile devices, risk management, mobile security, risk assessment

Citation

Janssen, J & Spruit, M 2019, M-RAM: a Mobile Risk Assessment Method for Enterprise Mobile Security. Technical Report Series, no. UU-CS-2019-009, UU BETA ICS Departement Informatica, Utrecht.