3 ms·
Ask. Since this often affects larger enterprises, start at the help/service desk. If that doesn't get you an answer, try Information Assurance or Information Se
by souterrain 7y ago
Ask. Since this often affects larger enterprises, start at the help/service desk. If that doesn't get you an answer, try Information Assurance or Information Security departments. Lastly, most large orgs have a Privacy office.
During all communications, make it clear what your concerns are; perhaps even link to articles like this one.
Corporations that care about customer and employee privacy will take such inquiries seriously.
- alistairSH 7y agoSure, but I assume there's something in the device itself that indicates there is a profile or remote access? I don't see a work-related profile on my phone, but maybe there's something else beyond the obvious Profiles entry in General settings?
- souterrain 7y agoThis is why I frame this as an ethics issue. If you install some sort of MDM profile, unless you spend a lot of time understanding mobile device management implementations, you won't necessarily know what the capabilities are. If it is your device, typically an employer will disclose in their policies what capabilities they use. Now, does this prevent a rogue infosec person from deviating from the policy? No. Nor does it prevent the state from compelling the company to abuse their MDM technology. If these examples are part of your threat model, you should not use your personal device with your employer's infrastructure. I don't think this makes your employer's choice to use MDM a bad one, however. They are protecting the corporation, after all.
- cj 7y ago> Ask. This is a good recommendation.